İçeriğe atla
Noroxi

CWE-281 · 321 kayıt

Improper Preservation of Permissions

Bu sınıftaki CVE’ler

321 kayıt

  • Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Win

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %74

    microsoft · windows 10 150714 Haz 2017

  • CVE-2019-0233
    50Planlayın

    An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.

    YüksekCVSS 7,5İstismar yokEPSS %68

    apache · struts14 Eyl 2020

  • CVE-2017-8589
    47Planlayın

    Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 15

    KritikCVSS 9,8İstismar yokEPSS %26

    microsoft · windows 1011 Tem 2017

  • CVE-2021-33990
    43Planlayın

    Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.

    KritikCVSS 9,8Kavram kanıtıEPSS %12

    liferay · liferay portal16 Nis 2023

  • CVE-2023-34034
    40Planlayın

    Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Sp

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    vmware · spring security19 Tem 2023

  • CVE-2018-4115
    40Planlayın

    An issue was discovered in certain Apple products.

    KritikCVSS 9,8İstismar yokEPSS %2

    apple · iphone os3 Nis 2018

  • CVE-2024-36532
    40Planlayın

    Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's t

    KritikCVSS 10,0İstismar yokEPSS %0

    21 Haz 2024

  • CVE-2020-18890
    39İzleyin

    Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via

    KritikCVSS 9,8İstismar yokEPSS %2

    puppycms · puppycms6 May 2021

  • CVE-2023-47463
    39İzleyin

    Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a cra

    KritikCVSS 9,8İstismar yokEPSS %1

    gl-inet · gl-ax1800 firmware30 Kas 2023

  • CVE-2020-36070
    39İzleyin

    Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php fi

    KritikCVSS 9,8İstismar yokEPSS %1

    thecontrolgroup · voyager26 Nis 2023

  • CVE-2021-29971
    39İzleyin

    If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port

    KritikCVSS 9,8İstismar yokEPSS %1

    mozilla · firefox5 Ağu 2021

  • CVE-2024-54465
    39İzleyin

    A logic issue was addressed with improved state management.

    KritikCVSS 9,8İstismar yokEPSS %1

    apple · macos11 Ara 2024

  • CVE-2024-56973
    39İzleyin

    Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary

    KritikCVSS 9,8İstismar yokEPSS %1

    14 Şub 2025

  • CVE-2023-28668
    39İzleyin

    Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.

    KritikCVSS 9,8İstismar yokEPSS %1

    jenkins · role-based authorization strategy2 Nis 2023

  • CVE-2024-41644
    39İzleyin

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    KritikCVSS 9,8İstismar yokEPSS %1

    openrobotics · robot operating system6 Ara 2024

  • CVE-2024-41646
    39İzleyin

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    KritikCVSS 9,8İstismar yokEPSS %1

    openrobotics · robot operating system6 Ara 2024

  • CVE-2024-41649
    39İzleyin

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    KritikCVSS 9,8İstismar yokEPSS %1

    openrobotics · robot operating system6 Ara 2024

  • CVE-2024-41645
    39İzleyin

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    KritikCVSS 9,8İstismar yokEPSS %1

    openrobotics · robot operating system6 Ara 2024

  • CVE-2024-55507
    39İzleyin

    An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.

    KritikCVSS 9,8İstismar yokEPSS %1

    codeastro · complaint management system3 Oca 2025

  • CVE-2024-46622
    39İzleyin

    An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8

    KritikCVSS 9,8İstismar yokEPSS %1

    6 Oca 2025

  • CVE-2024-41648
    39İzleyin

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    KritikCVSS 9,8İstismar yokEPSS %0

    openrobotics · robot operating system6 Ara 2024

  • CVE-2024-41650
    39İzleyin

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbit

    KritikCVSS 9,8İstismar yokEPSS %0

    openrobotics · robot operating system6 Ara 2024

  • Object state limitation has no effect

    KritikCVSS 9,5İstismar yok

    Packagist · ibexa/core29 Nis 2022

  • Object state limitation has no effect

    KritikCVSS 9,5İstismar yok

    Packagist · ezsystems/ezplatform-kernel29 Nis 2022

  • CVE-2024-46310
    37İzleyin

    Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via expose

    KritikCVSS 9,1Kavram kanıtıEPSS %2

    13 Oca 2025

Tüm zafiyet sınıfları