Vulnerabilities > Incorrect Permission Assignment for Critical Resource

DATE CVE VULNERABILITY TITLE RISK
2023-06-01 CVE-2023-28399 Incorrect Permission Assignment for Critical Resource vulnerability in Contec Conprosys HMI System
Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3.
local
low complexity
contec CWE-732
7.8
2023-05-31 CVE-2023-28346 Incorrect Permission Assignment for Critical Resource vulnerability in Faronics Insight 10.0.19045
An issue was discovered in Faronics Insight 10.0.19045 on Windows.
low complexity
faronics CWE-732
7.3
2023-05-29 CVE-2022-41766 Incorrect Permission Assignment for Critical Resource vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3.
network
low complexity
mediawiki CWE-732
4.3
2023-05-29 CVE-2023-31874 Incorrect Permission Assignment for Critical Resource vulnerability in Yank-Note Yank Note 3.52.1
Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_process').
network
low complexity
yank-note CWE-732
8.8
2023-05-24 CVE-2023-31748 Incorrect Permission Assignment for Critical Resource vulnerability in Wondershare Mobiletrans 4.0.11
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file.
local
low complexity
wondershare CWE-732
7.8
2023-05-22 CVE-2023-31454 Incorrect Permission Assignment for Critical Resource vulnerability in Apache Inlong
Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.  The attacker can bind any cluster, even if he is not the cluster owner.
network
low complexity
apache CWE-732
7.5
2023-05-20 CVE-2023-1692 Incorrect Permission Assignment for Critical Resource vulnerability in Huawei Emui and Harmonyos
The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.
network
low complexity
huawei CWE-732
7.5
2023-05-16 CVE-2023-32990 Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins Azure VM Agents
A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method.
network
low complexity
jenkins CWE-732
6.5
2023-05-16 CVE-2023-32992 Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins Saml Single Sign on
Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML.
network
low complexity
jenkins CWE-732
8.8
2023-05-16 CVE-2023-33004 Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins TAG Profiler
A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission to reset profiler statistics.
network
low complexity
jenkins CWE-732
4.3