CWE-281 · 321 kayıt
Improper Preservation of Permissions
Bu sınıftaki CVE’ler
321 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
91Hemen | CVE-2017-8543Silahlaştırılmış | Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Winmicrosoft · windows 10 1507 · CWE-281 | Kritik9,8 | KEV | %74,2 | 14 Haz 2017 |
50Planlayın | CVE-2019-0233İstismar yok | An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.apache · struts · CWE-281 | Yüksek7,5 | — | %68,1 | 14 Eyl 2020 |
47Planlayın | CVE-2017-8589İstismar yok | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 15microsoft · windows 10 · CWE-281 | Kritik9,8 | — | %26,2 | 11 Tem 2017 |
43Planlayın | CVE-2021-33990Kavram kanıtı | Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.liferay · liferay portal · CWE-281 | Kritik9,8 | — | %11,9 | 16 Nis 2023 |
40Planlayın | CVE-2023-34034Kavram kanıtı | Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spvmware · spring security · CWE-281 | Kritik9,8 | — | %4,0 | 19 Tem 2023 |
40Planlayın | CVE-2018-4115İstismar yok | An issue was discovered in certain Apple products.apple · iphone os · CWE-281 | Kritik9,8 | — | %2,2 | 3 Nis 2018 |
40Planlayın | CVE-2024-36532İstismar yok | Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tCWE-281 | Kritik10,0 | — | %0,5 | 21 Haz 2024 |
39İzleyin | CVE-2020-18890İstismar yok | Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via puppycms · puppycms · CWE-281 | Kritik9,8 | — | %1,5 | 6 May 2021 |
39İzleyin | CVE-2023-47463İstismar yok | Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a cragl-inet · gl-ax1800 firmware · CWE-281 | Kritik9,8 | — | %1,3 | 30 Kas 2023 |
39İzleyin | CVE-2020-36070İstismar yok | Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php fithecontrolgroup · voyager · CWE-281 | Kritik9,8 | — | %1,1 | 26 Nis 2023 |
39İzleyin | CVE-2021-29971İstismar yok | If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port mozilla · firefox · CWE-281 | Kritik9,8 | — | %1,0 | 5 Ağu 2021 |
39İzleyin | CVE-2024-54465İstismar yok | A logic issue was addressed with improved state management.apple · macos · CWE-281 | Kritik9,8 | — | %0,9 | 11 Ara 2024 |
39İzleyin | CVE-2024-56973İstismar yok | Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitraryCWE-281 | Kritik9,8 | — | %0,9 | 14 Şub 2025 |
39İzleyin | CVE-2023-28668İstismar yok | Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.jenkins · role-based authorization strategy · CWE-281 | Kritik9,8 | — | %0,8 | 2 Nis 2023 |
39İzleyin | CVE-2024-41644İstismar yok | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Kritik9,8 | — | %0,7 | 6 Ara 2024 |
39İzleyin | CVE-2024-41646İstismar yok | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Kritik9,8 | — | %0,7 | 6 Ara 2024 |
39İzleyin | CVE-2024-41649İstismar yok | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Kritik9,8 | — | %0,7 | 6 Ara 2024 |
39İzleyin | CVE-2024-41645İstismar yok | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Kritik9,8 | — | %0,7 | 6 Ara 2024 |
39İzleyin | CVE-2024-55507İstismar yok | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.codeastro · complaint management system · CWE-281 | Kritik9,8 | — | %0,6 | 3 Oca 2025 |
39İzleyin | CVE-2024-46622İstismar yok | An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8CWE-281 | Kritik9,8 | — | %0,6 | 6 Oca 2025 |
39İzleyin | CVE-2024-41648İstismar yok | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Kritik9,8 | — | %0,5 | 6 Ara 2024 |
39İzleyin | CVE-2024-41650İstismar yok | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitopenrobotics · robot operating system · CWE-281 | Kritik9,8 | — | %0,5 | 6 Ara 2024 |
38İzleyin | GHSA-gvj8-4cj4-h776İstismar yok | Object state limitation has no effectPackagist · ibexa/core · CWE-281 | Kritik9,5 | — | — | 29 Nis 2022 |
38İzleyin | GHSA-w8qp-hmh5-4v9vİstismar yok | Object state limitation has no effectPackagist · ezsystems/ezplatform-kernel · CWE-281 | Kritik9,5 | — | — | 29 Nis 2022 |
37İzleyin | CVE-2024-46310Kavram kanıtı | Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposeCWE-281 | Kritik9,1 | — | %2,5 | 13 Oca 2025 |
- CVE-2017-854391Hemen
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Win
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %74microsoft · windows 10 150714 Haz 2017
- CVE-2019-023350Planlayın
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
YüksekCVSS 7,5İstismar yokEPSS %68apache · struts14 Eyl 2020
- CVE-2017-858947Planlayın
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 15
KritikCVSS 9,8İstismar yokEPSS %26microsoft · windows 1011 Tem 2017
- CVE-2021-3399043Planlayın
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.
KritikCVSS 9,8Kavram kanıtıEPSS %12liferay · liferay portal16 Nis 2023
- CVE-2023-3403440Planlayın
Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Sp
KritikCVSS 9,8Kavram kanıtıEPSS %4vmware · spring security19 Tem 2023
- CVE-2018-411540Planlayın
An issue was discovered in certain Apple products.
KritikCVSS 9,8İstismar yokEPSS %2apple · iphone os3 Nis 2018
- CVE-2024-3653240Planlayın
Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's t
KritikCVSS 10,0İstismar yokEPSS %021 Haz 2024
- CVE-2020-1889039İzleyin
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via
KritikCVSS 9,8İstismar yokEPSS %2puppycms · puppycms6 May 2021
- CVE-2023-4746339İzleyin
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a cra
KritikCVSS 9,8İstismar yokEPSS %1gl-inet · gl-ax1800 firmware30 Kas 2023
- CVE-2020-3607039İzleyin
Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php fi
KritikCVSS 9,8İstismar yokEPSS %1thecontrolgroup · voyager26 Nis 2023
- CVE-2021-2997139İzleyin
If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port
KritikCVSS 9,8İstismar yokEPSS %1mozilla · firefox5 Ağu 2021
- CVE-2024-5446539İzleyin
A logic issue was addressed with improved state management.
KritikCVSS 9,8İstismar yokEPSS %1apple · macos11 Ara 2024
- CVE-2024-5697339İzleyin
Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary
KritikCVSS 9,8İstismar yokEPSS %114 Şub 2025
- CVE-2023-2866839İzleyin
Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.
KritikCVSS 9,8İstismar yokEPSS %1jenkins · role-based authorization strategy2 Nis 2023
- CVE-2024-4164439İzleyin
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
KritikCVSS 9,8İstismar yokEPSS %1openrobotics · robot operating system6 Ara 2024
- CVE-2024-4164639İzleyin
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
KritikCVSS 9,8İstismar yokEPSS %1openrobotics · robot operating system6 Ara 2024
- CVE-2024-4164939İzleyin
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
KritikCVSS 9,8İstismar yokEPSS %1openrobotics · robot operating system6 Ara 2024
- CVE-2024-4164539İzleyin
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
KritikCVSS 9,8İstismar yokEPSS %1openrobotics · robot operating system6 Ara 2024
- CVE-2024-5550739İzleyin
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
KritikCVSS 9,8İstismar yokEPSS %1codeastro · complaint management system3 Oca 2025
- CVE-2024-4662239İzleyin
An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8
KritikCVSS 9,8İstismar yokEPSS %16 Oca 2025
- CVE-2024-4164839İzleyin
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
KritikCVSS 9,8İstismar yokEPSS %0openrobotics · robot operating system6 Ara 2024
- CVE-2024-4165039İzleyin
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit
KritikCVSS 9,8İstismar yokEPSS %0openrobotics · robot operating system6 Ara 2024
- GHSA-gvj8-4cj4-h77638İzleyin
Object state limitation has no effect
KritikCVSS 9,5İstismar yokPackagist · ibexa/core29 Nis 2022
- GHSA-w8qp-hmh5-4v9v38İzleyin
Object state limitation has no effect
KritikCVSS 9,5İstismar yokPackagist · ezsystems/ezplatform-kernel29 Nis 2022
- CVE-2024-4631037İzleyin
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via expose
KritikCVSS 9,1Kavram kanıtıEPSS %213 Oca 2025