İçeriğe atla
Noroxi

CWE-276 · 1.435 kayıt

Incorrect Default Permissions

Bu sınıftaki CVE’ler

1.435 kayıt

  • administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitr

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94

    adobe · coldfusion16 Oca 2013

  • CVE-2017-11610
    61Bu hafta

    The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated us

    YüksekCVSS 8,8SilahlaştırılmışEPSS %87

    supervisord · supervisor23 Ağu 2017

  • CVE-2026-87886
    61Bu hafta

    Local privilege escalation due to insecure file permissions.

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %0

    acronis · acronis backup17 Eyl 2026

  • CVE-2022-22948
    60Bu hafta

    The vCenter Server contains an information disclosure vulnerability due to improper permission of files.

    OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %13

    vmware · cloud foundation29 Mar 2022

  • CVE-2023-29919
    54Planlayın

    SolarView Compact <= 6.0 is vulnerable to Insecure Permissions.

    KritikCVSS 9,1Kavram kanıtıEPSS %60

    contec · solarview compact firmware22 May 2023

  • CVE-2019-17124
    46Planlayın

    Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.

    KritikCVSS 9,8Kavram kanıtıEPSS %23

    kramerav · viaware9 Eki 2019

  • CVE-2021-3437
    44Planlayın

    Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or den

    KritikCVSS 9,8İstismar yokEPSS %16

    hp · omen gaming hub12 Ara 2022

  • CVE-2024-57684
    43Planlayın

    An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the D

    KritikCVSS 9,8İstismar yokEPSS %14

    dlink · dir-816 firmware16 Oca 2025

  • CVE-2020-12834
    42Planlayın

    eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.ru

    KritikCVSS 9,8İstismar yokEPSS %11

    eq-3 · homematic ccu2 firmware15 May 2020

  • CVE-1999-0426
    42Planlayın

    The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.

    KritikCVSS 9,8Kavram kanıtıEPSS %11

    suse · suse linux1 Mar 1999

  • CVE-2023-26918
    41Planlayın

    Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be e

    KritikCVSS 9,8Kavram kanıtıEPSS %6

    filereplicationpro · file replication pro13 Nis 2023

  • CVE-2023-31067
    41Planlayın

    An issue was discovered in TSplus Remote Access through 16.0.2.14.

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    tsplus · tsplus remote access11 Eyl 2023

  • CVE-2023-31068
    41Planlayın

    An issue was discovered in TSplus Remote Access through 16.0.2.14.

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    tsplus · tsplus remote work11 Eyl 2023

  • CVE-2020-29492
    41Planlayın

    Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability.

    KritikCVSS 10,0İstismar yokEPSS %2

    dell · wyse thinos4 Oca 2021

  • CVE-2017-8625
    40Planlayın

    Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Int

    YüksekCVSS 8,8Kavram kanıtıEPSS %15

    microsoft · internet explorer8 Ağu 2017

  • CVE-2020-9039
    40Planlayın

    Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the pro

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    couchbase · couchbase server21 Şub 2020

  • CVE-2021-36363
    40Planlayın

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

    KritikCVSS 9,8İstismar yokEPSS %4

    nagios · nagios xi28 Eyl 2021

  • CVE-2021-36365
    40Planlayın

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

    KritikCVSS 9,8İstismar yokEPSS %4

    nagios · nagios xi28 Eyl 2021

  • CVE-2020-9409
    40Planlayın

    TIBCO JasperReports Server Fails To Enforce Access Restrictions

    KritikCVSS 9,8İstismar yokEPSS %3

    tibco · jasperreports server20 May 2020

  • CVE-2021-39274
    40Planlayın

    In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user

    KritikCVSS 9,8İstismar yokEPSS %3

    xerosecurity · sn1per19 Ağu 2021

  • CVE-2019-19896
    40Planlayın

    In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share.

    KritikCVSS 9,9İstismar yokEPSS %3

    ixpdata · easyinstall23 Oca 2020

  • CVE-2021-45003
    40Planlayın

    Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.

    KritikCVSS 9,8İstismar yokEPSS %3

    nikhil-bhalerao · laundry booking management system10 Oca 2022

  • CVE-2020-13452
    40Planlayın

    In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file,

    KritikCVSS 9,8İstismar yokEPSS %3

    thecodingmachine · gotenberg7 Oca 2021

  • CVE-2022-27773
    40Planlayın

    A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elev

    KritikCVSS 9,8İstismar yokEPSS %3

    ivanti · endpoint manager5 Ara 2022

  • CVE-2019-12450
    40Planlayın

    file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is

    KritikCVSS 9,8İstismar yokEPSS %3

    gnome · glib29 May 2019

Tüm zafiyet sınıfları