Total
341 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-38577 | 1 Processmaker | 1 Processmaker | 2026-07-09 | N/A | 8.8 HIGH |
| ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators. | |||||
| CVE-2022-24618 | 1 Heimdalsecurity | 1 Heimdal Premium Security | 2026-07-09 | 7.2 HIGH | 7.8 HIGH |
| Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer. | |||||
| CVE-2024-54879 | 1 Seacms | 1 Seacms | 2026-07-05 | N/A | 9.1 CRITICAL |
| SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely. | |||||
| CVE-2024-46310 | 2026-07-05 | N/A | 9.1 CRITICAL | ||
| Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary user data via exposed API endpoint | |||||
| CVE-2026-44947 | 2026-07-02 | N/A | N/A | ||
| A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 allowed users to retain unauthorized Pod Security Admission (PSA) permissions after an administrator removes those permissions from a RoleTemplate. | |||||
| CVE-2025-9615 | 2026-06-30 | N/A | 3.3 LOW | ||
| A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection. | |||||
| CVE-2026-40767 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions. | |||||
| CVE-2026-35361 | 1 Uutils | 1 Coreutils | 2026-06-17 | N/A | 3.4 LOW |
| The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the utility attempts cleanup using std::fs::remove_dir, which cannot remove device nodes or FIFOs. This leaves mislabeled nodes behind with incorrect default contexts, potentially allowing unauthorized access to device nodes that should have been restricted by mandatory access controls. | |||||
| CVE-2026-35351 | 1 Uutils | 1 Coreutils | 2026-06-17 | N/A | 4.2 MEDIUM |
| The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries. The utility falls back to a copy-and-delete routine that creates the destination file using the caller's UID/GID rather than the source's metadata. This flaw breaks backups and migrations, causing files moved by a privileged user (e.g., root) to become root-owned unexpectedly, which can lead to information disclosure or restricted access for the intended owners. | |||||
| CVE-2026-35350 | 1 Uutils | 1 Coreutils | 2026-06-17 | N/A | 6.6 MEDIUM |
| The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. When copying with the -p (preserve) flag, the utility applies the source mode bits even if the chown operation is unsuccessful. This can result in a user-owned copy retaining original privileged bits, creating unexpected privileged executables that violate local security policies. This differs from GNU cp, which clears these bits when ownership cannot be preserved. | |||||
| CVE-2025-8325 | 1 Wso2 | 4 Api Control Plane, Api Manager, Traffic Manager and 1 more | 2026-06-17 | N/A | 6.3 MEDIUM |
| The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions. A malicious actor with a valid user account on a vulnerable deployment can perform sensitive operations against the Gateway REST API regardless of their actual roles or privileges. This could lead to unintended behavior or misuse, particularly in production environments. | |||||
| CVE-2025-7346 | 2026-06-17 | N/A | N/A | ||
| Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages | |||||
| CVE-2025-69875 | 1 Quickheal | 1 Total Security | 2026-06-17 | N/A | 7.8 HIGH |
| A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local attacker to place files in high-privilege locations, potentially leading to privilege escalation. | |||||
| CVE-2025-43701 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data. This impacts OmniStudio: before version 254. | |||||
| CVE-2025-43700 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025. | |||||
| CVE-2025-43698 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects. This impacts OmniStudio: before Spring 2025 | |||||
| CVE-2025-43697 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025 | |||||
| CVE-2025-43026 | 1 Hp | 1 Support Assistant | 2026-06-17 | N/A | 7.8 HIGH |
| A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write. | |||||
| CVE-2025-37735 | 2026-06-17 | N/A | 7.0 HIGH | ||
| Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege escalation. | |||||
| CVE-2025-34298 | 1 Nagios | 1 Log Server | 2026-06-17 | N/A | 8.8 HIGH |
| Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that granted elevated privileges or bypassed intended access controls. | |||||
