CWE-281 · 321 записей
Improper Preservation of Permissions
CVE этого класса
321 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
91Срочно | CVE-2017-8543Готовый эксплойт | Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Winmicrosoft · windows 10 1507 · CWE-281 | Критическая9,8 | KEV | 74,2 % | 14 июн. 2017 г. |
50В плане | CVE-2019-0233Эксплойта нет | An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.apache · struts · CWE-281 | Высокая7,5 | — | 68,1 % | 14 сент. 2020 г. |
47В плане | CVE-2017-8589Эксплойта нет | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 15microsoft · windows 10 · CWE-281 | Критическая9,8 | — | 26,2 % | 11 июл. 2017 г. |
43В плане | CVE-2021-33990Proof of concept | Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.liferay · liferay portal · CWE-281 | Критическая9,8 | — | 11,9 % | 16 апр. 2023 г. |
40В плане | CVE-2023-34034Proof of concept | Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spvmware · spring security · CWE-281 | Критическая9,8 | — | 4,0 % | 19 июл. 2023 г. |
40В плане | CVE-2018-4115Эксплойта нет | An issue was discovered in certain Apple products.apple · iphone os · CWE-281 | Критическая9,8 | — | 2,2 % | 3 апр. 2018 г. |
40В плане | CVE-2024-36532Эксплойта нет | Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tCWE-281 | Критическая10,0 | — | 0,5 % | 21 июн. 2024 г. |
39Наблюдать | CVE-2020-18890Эксплойта нет | Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via puppycms · puppycms · CWE-281 | Критическая9,8 | — | 1,5 % | 6 мая 2021 г. |
39Наблюдать | CVE-2023-47463Эксплойта нет | Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a cragl-inet · gl-ax1800 firmware · CWE-281 | Критическая9,8 | — | 1,3 % | 30 нояб. 2023 г. |
39Наблюдать | CVE-2020-36070Эксплойта нет | Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php fithecontrolgroup · voyager · CWE-281 | Критическая9,8 | — | 1,1 % | 26 апр. 2023 г. |
39Наблюдать | CVE-2021-29971Эксплойта нет | If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port mozilla · firefox · CWE-281 | Критическая9,8 | — | 1,0 % | 5 авг. 2021 г. |
39Наблюдать | CVE-2024-54465Эксплойта нет | A logic issue was addressed with improved state management.apple · macos · CWE-281 | Критическая9,8 | — | 0,9 % | 11 дек. 2024 г. |
39Наблюдать | CVE-2024-56973Эксплойта нет | Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitraryCWE-281 | Критическая9,8 | — | 0,9 % | 14 февр. 2025 г. |
39Наблюдать | CVE-2023-28668Эксплойта нет | Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.jenkins · role-based authorization strategy · CWE-281 | Критическая9,8 | — | 0,8 % | 2 апр. 2023 г. |
39Наблюдать | CVE-2024-41644Эксплойта нет | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Критическая9,8 | — | 0,7 % | 6 дек. 2024 г. |
39Наблюдать | CVE-2024-41646Эксплойта нет | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Критическая9,8 | — | 0,7 % | 6 дек. 2024 г. |
39Наблюдать | CVE-2024-41649Эксплойта нет | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Критическая9,8 | — | 0,7 % | 6 дек. 2024 г. |
39Наблюдать | CVE-2024-41645Эксплойта нет | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Критическая9,8 | — | 0,7 % | 6 дек. 2024 г. |
39Наблюдать | CVE-2024-55507Эксплойта нет | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.codeastro · complaint management system · CWE-281 | Критическая9,8 | — | 0,6 % | 3 янв. 2025 г. |
39Наблюдать | CVE-2024-46622Эксплойта нет | An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8CWE-281 | Критическая9,8 | — | 0,6 % | 6 янв. 2025 г. |
39Наблюдать | CVE-2024-41648Эксплойта нет | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Критическая9,8 | — | 0,5 % | 6 дек. 2024 г. |
39Наблюдать | CVE-2024-41650Эксплойта нет | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Критическая9,8 | — | 0,5 % | 6 дек. 2024 г. |
38Наблюдать | GHSA-gvj8-4cj4-h776Эксплойта нет | Object state limitation has no effectPackagist · ibexa/core · CWE-281 | Критическая9,5 | — | — | 29 апр. 2022 г. |
38Наблюдать | GHSA-w8qp-hmh5-4v9vЭксплойта нет | Object state limitation has no effectPackagist · ezsystems/ezplatform-kernel · CWE-281 | Критическая9,5 | — | — | 29 апр. 2022 г. |
37Наблюдать | CVE-2024-46310Proof of concept | Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposeCWE-281 | Критическая9,1 | — | 2,5 % | 13 янв. 2025 г. |
- CVE-2017-854391Срочно
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Win
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 74 %microsoft · windows 10 150714 июн. 2017 г.
- CVE-2019-023350В плане
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
ВысокаяCVSS 7,5Эксплойта нетEPSS 68 %apache · struts14 сент. 2020 г.
- CVE-2017-858947В плане
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 15
КритическаяCVSS 9,8Эксплойта нетEPSS 26 %microsoft · windows 1011 июл. 2017 г.
- CVE-2021-3399043В плане
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.
КритическаяCVSS 9,8Proof of conceptEPSS 12 %liferay · liferay portal16 апр. 2023 г.
- CVE-2023-3403440В плане
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Sp
КритическаяCVSS 9,8Proof of conceptEPSS 4 %vmware · spring security19 июл. 2023 г.
- CVE-2018-411540В плане
An issue was discovered in certain Apple products.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %apple · iphone os3 апр. 2018 г.
- CVE-2024-3653240В плане
Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's t
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %21 июн. 2024 г.
- CVE-2020-1889039Наблюдать
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %puppycms · puppycms6 мая 2021 г.
- CVE-2023-4746339Наблюдать
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a cra
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gl-inet · gl-ax1800 firmware30 нояб. 2023 г.
- CVE-2020-3607039Наблюдать
Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php fi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %thecontrolgroup · voyager26 апр. 2023 г.
- CVE-2021-2997139Наблюдать
If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mozilla · firefox5 авг. 2021 г.
- CVE-2024-5446539Наблюдать
A logic issue was addressed with improved state management.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apple · macos11 дек. 2024 г.
- CVE-2024-5697339Наблюдать
Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %14 февр. 2025 г.
- CVE-2023-2866839Наблюдать
Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %jenkins · role-based authorization strategy2 апр. 2023 г.
- CVE-2024-4164439Наблюдать
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openrobotics · robot operating system6 дек. 2024 г.
- CVE-2024-4164639Наблюдать
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openrobotics · robot operating system6 дек. 2024 г.
- CVE-2024-4164939Наблюдать
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openrobotics · robot operating system6 дек. 2024 г.
- CVE-2024-4164539Наблюдать
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openrobotics · robot operating system6 дек. 2024 г.
- CVE-2024-5550739Наблюдать
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %codeastro · complaint management system3 янв. 2025 г.
- CVE-2024-4662239Наблюдать
An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %6 янв. 2025 г.
- CVE-2024-4164839Наблюдать
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %openrobotics · robot operating system6 дек. 2024 г.
- CVE-2024-4165039Наблюдать
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %openrobotics · robot operating system6 дек. 2024 г.
- GHSA-gvj8-4cj4-h77638Наблюдать
Object state limitation has no effect
КритическаяCVSS 9,5Эксплойта нетPackagist · ibexa/core29 апр. 2022 г.
- GHSA-w8qp-hmh5-4v9v38Наблюдать
Object state limitation has no effect
КритическаяCVSS 9,5Эксплойта нетPackagist · ezsystems/ezplatform-kernel29 апр. 2022 г.
- CVE-2024-4631037Наблюдать
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via expose
КритическаяCVSS 9,1Proof of conceptEPSS 2 %13 янв. 2025 г.