Перейти к содержимому
Noroxi

CWE-732 · 1 473 записей

Incorrect Permission Assignment for Critical Resource

CVE этого класса

1 476 записей

  • CVE-2019-15752
    76На этой неделе

    Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.ex

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 49 %

    docker · docker28 авг. 2019 г.

  • CVE-2022-22960
    72На этой неделе

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissio

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 36 %

    vmware · cloud foundation13 апр. 2022 г.

  • CVE-2011-3923
    66На этой неделе

    Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary

    КритическаяCVSS 9,8Готовый эксплойтEPSS 89 %

    apache · struts1 нояб. 2019 г.

  • CVE-2018-13374
    58В плане

    A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obt

    СредняяCVSS 4,3KEVГотовый эксплойтEPSS 38 %

    fortinet · fortiadc22 янв. 2019 г.

  • CVE-2023-32986
    53В плане

    Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File

    ВысокаяCVSS 8,8Эксплойта нетEPSS 61 %

    jenkins · file parameters16 мая 2023 г.

  • CVE-2017-16885
    49В плане

    Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Us

    КритическаяCVSS 9,8Proof of conceptEPSS 33 %

    fiberhome · lm53q1 firmware12 янв. 2018 г.

  • CVE-2018-1000207
    47В плане

    MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpt

    ВысокаяCVSS 7,2Эксплойта нетEPSS 64 %

    modx · modx revolution13 июл. 2018 г.

  • CVE-2018-4072
    43В плане

    An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink

    ВысокаяCVSS 8,8Эксплойта нетEPSS 26 %

    sierrawireless · airlink es450 firmware6 мая 2019 г.

  • CVE-2018-4073
    43В плане

    An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink

    ВысокаяCVSS 8,8Эксплойта нетEPSS 26 %

    sierrawireless · airlink es450 firmware6 мая 2019 г.

  • CVE-2018-10285
    43В плане

    The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms.

    КритическаяCVSS 9,8Proof of conceptEPSS 13 %

    ericssonlg · ipecs nms22 апр. 2018 г.

  • CVE-2018-1000226
    43В плане

    Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older version

    КритическаяCVSS 9,8Proof of conceptEPSS 13 %

    cobblerd · cobbler20 авг. 2018 г.

  • CVE-2020-11107
    42В плане

    An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.

    ВысокаяCVSS 8,8Proof of conceptEPSS 22 %

    apachefriends · xampp2 апр. 2020 г.

  • CVE-2022-43773
    42В плане

    Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource

    ВысокаяCVSS 8,8Эксплойта нетEPSS 22 %

    hitachi · vantara pentaho business analytics server3 апр. 2023 г.

  • CVE-2017-9462
    42В плане

    In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbi

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 22 %

    mercurial · mercurial6 июн. 2017 г.

  • CVE-2026-21902
    42В плане

    Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root

    КритическаяCVSS 9,3Proof of conceptEPSS 18 %

    juniper · junos os evolved25 февр. 2026 г.

  • CVE-2018-14916
    41В плане

    LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.

    КритическаяCVSS 9,1Proof of conceptEPSS 17 %

    loytec · lgate-902 firmware28 июн. 2019 г.

  • CVE-2017-8857
    41В плане

    In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote comman

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    veritas · netbackup9 мая 2017 г.

  • CVE-2019-7958
    40В плане

    Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    adobe · creative cloud16 авг. 2019 г.

  • CVE-2017-9602
    40В плане

    KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component.

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    kbvault mysql project · kbvault mysql16 июн. 2017 г.

  • CVE-2019-8256
    40В плане

    ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    adobe · coldfusion19 дек. 2019 г.

  • CVE-2020-9671
    40В плане

    Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    adobe · creative cloud desktop application16 июл. 2020 г.

  • CVE-2020-28910
    40В плане

    Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of s

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    nagios · nagios xi24 мая 2021 г.

  • CVE-2018-10381
    40В плане

    TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    mcafee · tunnelbear25 апр. 2018 г.

  • CVE-2017-8856
    40В плане

    In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution u

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    veritas · netbackup9 мая 2017 г.

  • CVE-2017-6950
    40В плане

    SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABA

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    sap · gui for windows23 мар. 2017 г.

Все классы уязвимостей