Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Android HIGH 7.8
CVE-2017-13312

In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escal…

Mitigation only
Fix from $1,950 2024-11-15
Android HIGH 7.8
CVE-2017-13314

In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This coul…

Patch available
Fix from $1,950 2024-11-15
Unclassified HIGH 7.8
CVE-2024-46462

By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform task…

Mitigation only
Fix from $1,950 2024-11-15
Unclassified HIGH 7.8
CVE-2024-46463

By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks…

Mitigation only
Fix from $1,950 2024-11-15
Cryhod HIGH 7.8
CVE-2024-46465

By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks…

Fix: after 2024.3
Fix from $1,950 2024-11-15
Unclassified HIGH 7.8
CVE-2024-46466

By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other use…

Mitigation only
Fix from $1,950 2024-11-15
Unclassified HIGH 7.8
CVE-2024-46467

By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform ta…

Mitigation only
Fix from $1,950 2024-11-15
Pipeline\ HIGH 8.0
CVE-2024-52551

Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a bui…

Fix: after 2.2214.vb_b_34b_2ea_9b_83
Fix from $1,950 2024-11-13
Server Debug And Provisioning Tool HIGH 7.8
CVE-2024-35201

Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of priv…

Mitigation only
Fix from $1,950 2024-11-13
Unclassified MEDIUM 6.7
CVE-2024-29083

Incorrect default permissions in some Intel(R) Distribution for Python software before version 2024.2 may allow an authenticated user to potentially …

Mitigation only
Fix from $1,600 2024-11-13
Unclassified MEDIUM 6.7
CVE-2024-25647

Incorrect default permissions for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may allow an authenticated user t…

Mitigation only
Fix from $1,600 2024-11-13
Unclassified HIGH 7.2
CVE-2024-21820

Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user…

Mitigation only
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-43085

In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic …

Patch available
Fix from $1,950 2024-11-13
Android MEDIUM 5.5
CVE-2024-43086

In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to a confused…

Patch available
Fix from $1,600 2024-11-13
Android HIGH 7.8
CVE-2024-43089

In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to loc…

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-40660

In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a logic error in the code. This c…

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-40661

In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission chec…

Patch available
Fix from $1,950 2024-11-13
Android HIGH 7.8
CVE-2024-43081

In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This c…

Patch available
Fix from $1,950 2024-11-13
Unclassified HIGH 7.0
CVE-2024-49504

grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.

Mitigation only
Fix from $1,950 2024-11-13
Management Console HIGH 7.3
CVE-2024-21957

Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentiall…

Fix: 10.0+
Fix from $1,950 2024-11-12
Provisioning Console HIGH 7.3
CVE-2024-21958

Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potenti…

Fix: 4.0.0.408+
Fix from $1,950 2024-11-12
Management Plugin For Sccm HIGH 7.8
CVE-2024-21938

Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could…

Fix: 7.0.0.1318+
Fix from $1,950 2024-11-12
Cloud Manageability Service HIGH 7.3
CVE-2024-21939

Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privil…

Fix: 2.0.0.232+
Fix from $1,950 2024-11-12
Ryzen Master Monitoring Software Development Kit HIGH 7.3
CVE-2024-21945

Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation…

Fix: 2.13.0.2915+
Fix from $1,950 2024-11-12
Ryzen Master Utility For Overclocking Control HIGH 7.3
CVE-2024-21946

Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potent…

Fix: 2.13.1.3097+
Fix from $1,950 2024-11-12
Radeon Software HIGH 7.8
CVE-2024-21937

Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting…

Fix: 24.q2 / 24.6.1+
Fix from $1,950 2024-11-12
Sinec Ins MEDIUM 5.4
CVE-2024-46894

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorizatio…

Fix: after 1.0
Fix from $1,600 2024-11-12
Moodle MEDIUM 5.3
CVE-2024-43430

A flaw was found in moodle. External API access to Quiz can override contained insufficient access control.

Fix: 4.4.2+
Fix from $1,600 2024-11-11
Unclassified HIGH 7.8
CVE-2024-50590

Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one o…

Mitigation only
Fix from $1,950 2024-11-08
Unclassified CRITICAL 9.8
CVE-2023-27195

Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve the last registration access co…

Mitigation only
Fix from $2,300 2024-11-08