Перейти к содержимому
Noroxi

CWE-281 · 321 записей

Improper Preservation of Permissions

CVE этого класса

321 записей

  • CVE-2017-8543
    91Срочно

    Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Win

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 74 %

    microsoft · windows 10 150714 июн. 2017 г.

  • CVE-2019-0233
    50В плане

    An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 68 %

    apache · struts14 сент. 2020 г.

  • CVE-2017-8589
    47В плане

    Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 15

    КритическаяCVSS 9,8Эксплойта нетEPSS 26 %

    microsoft · windows 1011 июл. 2017 г.

  • CVE-2021-33990
    43В плане

    Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.

    КритическаяCVSS 9,8Proof of conceptEPSS 12 %

    liferay · liferay portal16 апр. 2023 г.

  • CVE-2023-34034
    40В плане

    Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Sp

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    vmware · spring security19 июл. 2023 г.

  • CVE-2018-4115
    40В плане

    An issue was discovered in certain Apple products.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    apple · iphone os3 апр. 2018 г.

  • CVE-2024-36532
    40В плане

    Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's t

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    21 июн. 2024 г.

  • CVE-2020-18890
    39Наблюдать

    Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    puppycms · puppycms6 мая 2021 г.

  • CVE-2023-47463
    39Наблюдать

    Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a cra

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    gl-inet · gl-ax1800 firmware30 нояб. 2023 г.

  • CVE-2020-36070
    39Наблюдать

    Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php fi

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    thecontrolgroup · voyager26 апр. 2023 г.

  • CVE-2021-29971
    39Наблюдать

    If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mozilla · firefox5 авг. 2021 г.

  • CVE-2024-54465
    39Наблюдать

    A logic issue was addressed with improved state management.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apple · macos11 дек. 2024 г.

  • CVE-2024-56973
    39Наблюдать

    Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    14 февр. 2025 г.

  • CVE-2023-28668
    39Наблюдать

    Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    jenkins · role-based authorization strategy2 апр. 2023 г.

  • CVE-2024-41644
    39Наблюдать

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    openrobotics · robot operating system6 дек. 2024 г.

  • CVE-2024-41646
    39Наблюдать

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    openrobotics · robot operating system6 дек. 2024 г.

  • CVE-2024-41649
    39Наблюдать

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    openrobotics · robot operating system6 дек. 2024 г.

  • CVE-2024-41645
    39Наблюдать

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    openrobotics · robot operating system6 дек. 2024 г.

  • CVE-2024-55507
    39Наблюдать

    An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    codeastro · complaint management system3 янв. 2025 г.

  • CVE-2024-46622
    39Наблюдать

    An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    6 янв. 2025 г.

  • CVE-2024-41648
    39Наблюдать

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    openrobotics · robot operating system6 дек. 2024 г.

  • CVE-2024-41650
    39Наблюдать

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    openrobotics · robot operating system6 дек. 2024 г.

  • GHSA-gvj8-4cj4-h776
    38Наблюдать

    Object state limitation has no effect

    КритическаяCVSS 9,5Эксплойта нет

    Packagist · ibexa/core29 апр. 2022 г.

  • GHSA-w8qp-hmh5-4v9v
    38Наблюдать

    Object state limitation has no effect

    КритическаяCVSS 9,5Эксплойта нет

    Packagist · ezsystems/ezplatform-kernel29 апр. 2022 г.

  • CVE-2024-46310
    37Наблюдать

    Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via expose

    КритическаяCVSS 9,1Proof of conceptEPSS 2 %

    13 янв. 2025 г.

Все классы уязвимостей