CWE-276 · 1.435 kayıt
Incorrect Default Permissions
Bu sınıftaki CVE’ler
1.435 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
97Hemen | CVE-2013-0632Silahlaştırılmış | administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitradobe · coldfusion · CWE-276 | Kritik9,8 | KEV | %93,6 | 16 Oca 2013 |
61Bu hafta | CVE-2017-11610Silahlaştırılmış | The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated ussupervisord · supervisor · CWE-276 | Yüksek8,8 | — | %87,4 | 23 Ağu 2017 |
61Bu hafta | CVE-2026-87886Silahlaştırılmış | Local privilege escalation due to insecure file permissions.acronis · acronis backup · CWE-276 | Yüksek7,8 | KEV | %0,2 | 17 Eyl 2026 |
60Bu hafta | CVE-2022-22948Silahlaştırılmış | The vCenter Server contains an information disclosure vulnerability due to improper permission of files.vmware · cloud foundation · CWE-276 | Orta6,5 | KEV | %13,3 | 29 Mar 2022 |
54Planlayın | CVE-2023-29919Kavram kanıtı | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.contec · solarview compact firmware · CWE-276 | Kritik9,1 | — | %60,2 | 22 May 2023 |
46Planlayın | CVE-2019-17124Kavram kanıtı | Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.kramerav · viaware · CWE-276 | Kritik9,8 | — | %22,5 | 9 Eki 2019 |
44Planlayın | CVE-2021-3437İstismar yok | Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denhp · omen gaming hub · CWE-276 | Kritik9,8 | — | %15,6 | 12 Ara 2022 |
43Planlayın | CVE-2024-57684İstismar yok | An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the Ddlink · dir-816 firmware · CWE-276 | Kritik9,8 | — | %14,4 | 16 Oca 2025 |
42Planlayın | CVE-2020-12834İstismar yok | eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.rueq-3 · homematic ccu2 firmware · CWE-276 | Kritik9,8 | — | %11,1 | 15 May 2020 |
42Planlayın | CVE-1999-0426Kavram kanıtı | The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.suse · suse linux · CWE-276 | Kritik9,8 | — | %10,8 | 1 Mar 1999 |
41Planlayın | CVE-2023-26918Kavram kanıtı | Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be efilereplicationpro · file replication pro · CWE-276 | Kritik9,8 | — | %6,1 | 13 Nis 2023 |
41Planlayın | CVE-2023-31067Kavram kanıtı | An issue was discovered in TSplus Remote Access through 16.0.2.14.tsplus · tsplus remote access · CWE-276 | Kritik9,8 | — | %5,5 | 11 Eyl 2023 |
41Planlayın | CVE-2023-31068Kavram kanıtı | An issue was discovered in TSplus Remote Access through 16.0.2.14.tsplus · tsplus remote work · CWE-276 | Kritik9,8 | — | %5,4 | 11 Eyl 2023 |
41Planlayın | CVE-2020-29492İstismar yok | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability.dell · wyse thinos · CWE-276 | Kritik10,0 | — | %1,7 | 4 Oca 2021 |
40Planlayın | CVE-2017-8625Kavram kanıtı | Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Intmicrosoft · internet explorer · CWE-276 | Yüksek8,8 | — | %15,3 | 8 Ağu 2017 |
40Planlayın | CVE-2020-9039Kavram kanıtı | Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the procouchbase · couchbase server · CWE-276 | Kritik9,8 | — | %3,9 | 21 Şub 2020 |
40Planlayın | CVE-2021-36363İstismar yok | Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.nagios · nagios xi · CWE-276 | Kritik9,8 | — | %3,8 | 28 Eyl 2021 |
40Planlayın | CVE-2021-36365İstismar yok | Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.nagios · nagios xi · CWE-276 | Kritik9,8 | — | %3,8 | 28 Eyl 2021 |
40Planlayın | CVE-2020-9409İstismar yok | TIBCO JasperReports Server Fails To Enforce Access Restrictionstibco · jasperreports server · CWE-276 | Kritik9,8 | — | %3,4 | 20 May 2020 |
40Planlayın | CVE-2021-39274İstismar yok | In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user xerosecurity · sn1per · CWE-276 | Kritik9,8 | — | %3,1 | 19 Ağu 2021 |
40Planlayın | CVE-2019-19896İstismar yok | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share.ixpdata · easyinstall · CWE-276 | Kritik9,9 | — | %3,0 | 23 Oca 2020 |
40Planlayın | CVE-2021-45003İstismar yok | Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.nikhil-bhalerao · laundry booking management system · CWE-276 | Kritik9,8 | — | %3,0 | 10 Oca 2022 |
40Planlayın | CVE-2020-13452İstismar yok | In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, thecodingmachine · gotenberg · CWE-276 | Kritik9,8 | — | %2,7 | 7 Oca 2021 |
40Planlayın | CVE-2022-27773İstismar yok | A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevivanti · endpoint manager · CWE-276 | Kritik9,8 | — | %2,7 | 5 Ara 2022 |
40Planlayın | CVE-2019-12450İstismar yok | file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is gnome · glib · CWE-276 | Kritik9,8 | — | %2,6 | 29 May 2019 |
- CVE-2013-063297Hemen
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitr
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94adobe · coldfusion16 Oca 2013
- CVE-2017-1161061Bu hafta
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated us
YüksekCVSS 8,8SilahlaştırılmışEPSS %87supervisord · supervisor23 Ağu 2017
- CVE-2026-8788661Bu hafta
Local privilege escalation due to insecure file permissions.
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %0acronis · acronis backup17 Eyl 2026
- CVE-2022-2294860Bu hafta
The vCenter Server contains an information disclosure vulnerability due to improper permission of files.
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %13vmware · cloud foundation29 Mar 2022
- CVE-2023-2991954Planlayın
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.
KritikCVSS 9,1Kavram kanıtıEPSS %60contec · solarview compact firmware22 May 2023
- CVE-2019-1712446Planlayın
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
KritikCVSS 9,8Kavram kanıtıEPSS %23kramerav · viaware9 Eki 2019
- CVE-2021-343744Planlayın
Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or den
KritikCVSS 9,8İstismar yokEPSS %16hp · omen gaming hub12 Ara 2022
- CVE-2024-5768443Planlayın
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the D
KritikCVSS 9,8İstismar yokEPSS %14dlink · dir-816 firmware16 Oca 2025
- CVE-2020-1283442Planlayın
eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.ru
KritikCVSS 9,8İstismar yokEPSS %11eq-3 · homematic ccu2 firmware15 May 2020
- CVE-1999-042642Planlayın
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
KritikCVSS 9,8Kavram kanıtıEPSS %11suse · suse linux1 Mar 1999
- CVE-2023-2691841Planlayın
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be e
KritikCVSS 9,8Kavram kanıtıEPSS %6filereplicationpro · file replication pro13 Nis 2023
- CVE-2023-3106741Planlayın
An issue was discovered in TSplus Remote Access through 16.0.2.14.
KritikCVSS 9,8Kavram kanıtıEPSS %5tsplus · tsplus remote access11 Eyl 2023
- CVE-2023-3106841Planlayın
An issue was discovered in TSplus Remote Access through 16.0.2.14.
KritikCVSS 9,8Kavram kanıtıEPSS %5tsplus · tsplus remote work11 Eyl 2023
- CVE-2020-2949241Planlayın
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability.
KritikCVSS 10,0İstismar yokEPSS %2dell · wyse thinos4 Oca 2021
- CVE-2017-862540Planlayın
Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Int
YüksekCVSS 8,8Kavram kanıtıEPSS %15microsoft · internet explorer8 Ağu 2017
- CVE-2020-903940Planlayın
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the pro
KritikCVSS 9,8Kavram kanıtıEPSS %4couchbase · couchbase server21 Şub 2020
- CVE-2021-3636340Planlayın
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
KritikCVSS 9,8İstismar yokEPSS %4nagios · nagios xi28 Eyl 2021
- CVE-2021-3636540Planlayın
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
KritikCVSS 9,8İstismar yokEPSS %4nagios · nagios xi28 Eyl 2021
- CVE-2020-940940Planlayın
TIBCO JasperReports Server Fails To Enforce Access Restrictions
KritikCVSS 9,8İstismar yokEPSS %3tibco · jasperreports server20 May 2020
- CVE-2021-3927440Planlayın
In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user
KritikCVSS 9,8İstismar yokEPSS %3xerosecurity · sn1per19 Ağu 2021
- CVE-2019-1989640Planlayın
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share.
KritikCVSS 9,9İstismar yokEPSS %3ixpdata · easyinstall23 Oca 2020
- CVE-2021-4500340Planlayın
Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.
KritikCVSS 9,8İstismar yokEPSS %3nikhil-bhalerao · laundry booking management system10 Oca 2022
- CVE-2020-1345240Planlayın
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file,
KritikCVSS 9,8İstismar yokEPSS %3thecodingmachine · gotenberg7 Oca 2021
- CVE-2022-2777340Planlayın
A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elev
KritikCVSS 9,8İstismar yokEPSS %3ivanti · endpoint manager5 Ara 2022
- CVE-2019-1245040Planlayın
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is
KritikCVSS 9,8İstismar yokEPSS %3gnome · glib29 May 2019