CWE-276 · 1 435 записей
Incorrect Default Permissions
CVE этого класса
1 435 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
97Срочно | CVE-2013-0632Готовый эксплойт | administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitradobe · coldfusion · CWE-276 | Критическая9,8 | KEV | 93,6 % | 16 янв. 2013 г. |
61На этой неделе | CVE-2017-11610Готовый эксплойт | The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated ussupervisord · supervisor · CWE-276 | Высокая8,8 | — | 87,4 % | 23 авг. 2017 г. |
61На этой неделе | CVE-2026-87886Готовый эксплойт | Local privilege escalation due to insecure file permissions.acronis · acronis backup · CWE-276 | Высокая7,8 | KEV | 0,2 % | 17 сент. 2026 г. |
60На этой неделе | CVE-2022-22948Готовый эксплойт | The vCenter Server contains an information disclosure vulnerability due to improper permission of files.vmware · cloud foundation · CWE-276 | Средняя6,5 | KEV | 13,3 % | 29 мар. 2022 г. |
54В плане | CVE-2023-29919Proof of concept | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.contec · solarview compact firmware · CWE-276 | Критическая9,1 | — | 60,2 % | 22 мая 2023 г. |
46В плане | CVE-2019-17124Proof of concept | Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.kramerav · viaware · CWE-276 | Критическая9,8 | — | 22,5 % | 9 окт. 2019 г. |
44В плане | CVE-2021-3437Эксплойта нет | Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denhp · omen gaming hub · CWE-276 | Критическая9,8 | — | 15,6 % | 12 дек. 2022 г. |
43В плане | CVE-2024-57684Эксплойта нет | An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the Ddlink · dir-816 firmware · CWE-276 | Критическая9,8 | — | 14,4 % | 16 янв. 2025 г. |
42В плане | CVE-2020-12834Эксплойта нет | eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.rueq-3 · homematic ccu2 firmware · CWE-276 | Критическая9,8 | — | 11,1 % | 15 мая 2020 г. |
42В плане | CVE-1999-0426Proof of concept | The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.suse · suse linux · CWE-276 | Критическая9,8 | — | 10,8 % | 1 мар. 1999 г. |
41В плане | CVE-2023-26918Proof of concept | Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be efilereplicationpro · file replication pro · CWE-276 | Критическая9,8 | — | 6,1 % | 13 апр. 2023 г. |
41В плане | CVE-2023-31067Proof of concept | An issue was discovered in TSplus Remote Access through 16.0.2.14.tsplus · tsplus remote access · CWE-276 | Критическая9,8 | — | 5,5 % | 11 сент. 2023 г. |
41В плане | CVE-2023-31068Proof of concept | An issue was discovered in TSplus Remote Access through 16.0.2.14.tsplus · tsplus remote work · CWE-276 | Критическая9,8 | — | 5,4 % | 11 сент. 2023 г. |
41В плане | CVE-2020-29492Эксплойта нет | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability.dell · wyse thinos · CWE-276 | Критическая10,0 | — | 1,7 % | 4 янв. 2021 г. |
40В плане | CVE-2017-8625Proof of concept | Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Intmicrosoft · internet explorer · CWE-276 | Высокая8,8 | — | 15,3 % | 8 авг. 2017 г. |
40В плане | CVE-2020-9039Proof of concept | Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the procouchbase · couchbase server · CWE-276 | Критическая9,8 | — | 3,9 % | 21 февр. 2020 г. |
40В плане | CVE-2021-36363Эксплойта нет | Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.nagios · nagios xi · CWE-276 | Критическая9,8 | — | 3,8 % | 28 сент. 2021 г. |
40В плане | CVE-2021-36365Эксплойта нет | Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.nagios · nagios xi · CWE-276 | Критическая9,8 | — | 3,8 % | 28 сент. 2021 г. |
40В плане | CVE-2020-9409Эксплойта нет | TIBCO JasperReports Server Fails To Enforce Access Restrictionstibco · jasperreports server · CWE-276 | Критическая9,8 | — | 3,4 % | 20 мая 2020 г. |
40В плане | CVE-2021-39274Эксплойта нет | In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user xerosecurity · sn1per · CWE-276 | Критическая9,8 | — | 3,1 % | 19 авг. 2021 г. |
40В плане | CVE-2019-19896Эксплойта нет | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share.ixpdata · easyinstall · CWE-276 | Критическая9,9 | — | 3,0 % | 23 янв. 2020 г. |
40В плане | CVE-2021-45003Эксплойта нет | Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.nikhil-bhalerao · laundry booking management system · CWE-276 | Критическая9,8 | — | 3,0 % | 10 янв. 2022 г. |
40В плане | CVE-2020-13452Эксплойта нет | In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, thecodingmachine · gotenberg · CWE-276 | Критическая9,8 | — | 2,7 % | 7 янв. 2021 г. |
40В плане | CVE-2022-27773Эксплойта нет | A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevivanti · endpoint manager · CWE-276 | Критическая9,8 | — | 2,7 % | 5 дек. 2022 г. |
40В плане | CVE-2019-12450Эксплойта нет | file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is gnome · glib · CWE-276 | Критическая9,8 | — | 2,6 % | 29 мая 2019 г. |
- CVE-2013-063297Срочно
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitr
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · coldfusion16 янв. 2013 г.
- CVE-2017-1161061На этой неделе
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated us
ВысокаяCVSS 8,8Готовый эксплойтEPSS 87 %supervisord · supervisor23 авг. 2017 г.
- CVE-2026-8788661На этой неделе
Local privilege escalation due to insecure file permissions.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 0 %acronis · acronis backup17 сент. 2026 г.
- CVE-2022-2294860На этой неделе
The vCenter Server contains an information disclosure vulnerability due to improper permission of files.
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 13 %vmware · cloud foundation29 мар. 2022 г.
- CVE-2023-2991954В плане
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.
КритическаяCVSS 9,1Proof of conceptEPSS 60 %contec · solarview compact firmware22 мая 2023 г.
- CVE-2019-1712446В плане
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
КритическаяCVSS 9,8Proof of conceptEPSS 23 %kramerav · viaware9 окт. 2019 г.
- CVE-2021-343744В плане
Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or den
КритическаяCVSS 9,8Эксплойта нетEPSS 16 %hp · omen gaming hub12 дек. 2022 г.
- CVE-2024-5768443В плане
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the D
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %dlink · dir-816 firmware16 янв. 2025 г.
- CVE-2020-1283442В плане
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.ru
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %eq-3 · homematic ccu2 firmware15 мая 2020 г.
- CVE-1999-042642В плане
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
КритическаяCVSS 9,8Proof of conceptEPSS 11 %suse · suse linux1 мар. 1999 г.
- CVE-2023-2691841В плане
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be e
КритическаяCVSS 9,8Proof of conceptEPSS 6 %filereplicationpro · file replication pro13 апр. 2023 г.
- CVE-2023-3106741В плане
An issue was discovered in TSplus Remote Access through 16.0.2.14.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %tsplus · tsplus remote access11 сент. 2023 г.
- CVE-2023-3106841В плане
An issue was discovered in TSplus Remote Access through 16.0.2.14.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %tsplus · tsplus remote work11 сент. 2023 г.
- CVE-2020-2949241В плане
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %dell · wyse thinos4 янв. 2021 г.
- CVE-2017-862540В плане
Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Int
ВысокаяCVSS 8,8Proof of conceptEPSS 15 %microsoft · internet explorer8 авг. 2017 г.
- CVE-2020-903940В плане
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the pro
КритическаяCVSS 9,8Proof of conceptEPSS 4 %couchbase · couchbase server21 февр. 2020 г.
- CVE-2021-3636340В плане
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %nagios · nagios xi28 сент. 2021 г.
- CVE-2021-3636540В плане
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %nagios · nagios xi28 сент. 2021 г.
- CVE-2020-940940В плане
TIBCO JasperReports Server Fails To Enforce Access Restrictions
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %tibco · jasperreports server20 мая 2020 г.
- CVE-2021-3927440В плане
In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %xerosecurity · sn1per19 авг. 2021 г.
- CVE-2019-1989640В плане
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share.
КритическаяCVSS 9,9Эксплойта нетEPSS 3 %ixpdata · easyinstall23 янв. 2020 г.
- CVE-2021-4500340В плане
Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %nikhil-bhalerao · laundry booking management system10 янв. 2022 г.
- CVE-2020-1345240В плане
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file,
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %thecodingmachine · gotenberg7 янв. 2021 г.
- CVE-2022-2777340В плане
A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elev
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %ivanti · endpoint manager5 дек. 2022 г.
- CVE-2019-1245040В плане
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %gnome · glib29 мая 2019 г.