Перейти к содержимому
Noroxi

CWE-276 · 1 435 записей

Incorrect Default Permissions

CVE этого класса

1 435 записей

  • CVE-2013-0632
    97Срочно

    administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitr

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %

    adobe · coldfusion16 янв. 2013 г.

  • CVE-2017-11610
    61На этой неделе

    The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated us

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 87 %

    supervisord · supervisor23 авг. 2017 г.

  • CVE-2026-87886
    61На этой неделе

    Local privilege escalation due to insecure file permissions.

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 0 %

    acronis · acronis backup17 сент. 2026 г.

  • CVE-2022-22948
    60На этой неделе

    The vCenter Server contains an information disclosure vulnerability due to improper permission of files.

    СредняяCVSS 6,5KEVГотовый эксплойтEPSS 13 %

    vmware · cloud foundation29 мар. 2022 г.

  • CVE-2023-29919
    54В плане

    SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.

    КритическаяCVSS 9,1Proof of conceptEPSS 60 %

    contec · solarview compact firmware22 мая 2023 г.

  • CVE-2019-17124
    46В плане

    Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.

    КритическаяCVSS 9,8Proof of conceptEPSS 23 %

    kramerav · viaware9 окт. 2019 г.

  • CVE-2021-3437
    44В плане

    Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or den

    КритическаяCVSS 9,8Эксплойта нетEPSS 16 %

    hp · omen gaming hub12 дек. 2022 г.

  • CVE-2024-57684
    43В плане

    An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the D

    КритическаяCVSS 9,8Эксплойта нетEPSS 14 %

    dlink · dir-816 firmware16 янв. 2025 г.

  • CVE-2020-12834
    42В плане

    eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.ru

    КритическаяCVSS 9,8Эксплойта нетEPSS 11 %

    eq-3 · homematic ccu2 firmware15 мая 2020 г.

  • CVE-1999-0426
    42В плане

    The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.

    КритическаяCVSS 9,8Proof of conceptEPSS 11 %

    suse · suse linux1 мар. 1999 г.

  • CVE-2023-26918
    41В плане

    Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be e

    КритическаяCVSS 9,8Proof of conceptEPSS 6 %

    filereplicationpro · file replication pro13 апр. 2023 г.

  • CVE-2023-31067
    41В плане

    An issue was discovered in TSplus Remote Access through 16.0.2.14.

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    tsplus · tsplus remote access11 сент. 2023 г.

  • CVE-2023-31068
    41В плане

    An issue was discovered in TSplus Remote Access through 16.0.2.14.

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    tsplus · tsplus remote work11 сент. 2023 г.

  • CVE-2020-29492
    41В плане

    Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability.

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    dell · wyse thinos4 янв. 2021 г.

  • CVE-2017-8625
    40В плане

    Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Int

    ВысокаяCVSS 8,8Proof of conceptEPSS 15 %

    microsoft · internet explorer8 авг. 2017 г.

  • CVE-2020-9039
    40В плане

    Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the pro

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    couchbase · couchbase server21 февр. 2020 г.

  • CVE-2021-36363
    40В плане

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    nagios · nagios xi28 сент. 2021 г.

  • CVE-2021-36365
    40В плане

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    nagios · nagios xi28 сент. 2021 г.

  • CVE-2020-9409
    40В плане

    TIBCO JasperReports Server Fails To Enforce Access Restrictions

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    tibco · jasperreports server20 мая 2020 г.

  • CVE-2021-39274
    40В плане

    In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    xerosecurity · sn1per19 авг. 2021 г.

  • CVE-2019-19896
    40В плане

    In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share.

    КритическаяCVSS 9,9Эксплойта нетEPSS 3 %

    ixpdata · easyinstall23 янв. 2020 г.

  • CVE-2021-45003
    40В плане

    Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    nikhil-bhalerao · laundry booking management system10 янв. 2022 г.

  • CVE-2020-13452
    40В плане

    In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file,

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    thecodingmachine · gotenberg7 янв. 2021 г.

  • CVE-2022-27773
    40В плане

    A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elev

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    ivanti · endpoint manager5 дек. 2022 г.

  • CVE-2019-12450
    40В плане

    file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    gnome · glib29 мая 2019 г.

Все классы уязвимостей