Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Ai Virtual Presence Sensor HIGH 7.8
CVE-2023-3112

A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute co…

Fix: 3.1.50719.1+
Fix from $1,950 2023-10-25
Cloud Lab CRITICAL 10.0
CVE-2022-42150

TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause Container Es…

Patch available
Fix from $2,300 2023-10-19
Access Rights Manager HIGH 7.8
CVE-2023-35183

The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows authenticated users to abuse lo…

Fix: after 2023.2.0.73
Fix from $1,950 2023-10-19
Access Rights Manager HIGH 7.8
CVE-2023-35181

The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows users to abuse incorrect folder…

Fix: after 2023.2.0.73
Fix from $1,950 2023-10-19
Tsplus Remote Work CRITICAL 9.8
CVE-2023-27133

TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-RemoteWork\Clients\www folder. T…

Fix: after 16.0.0.0
Fix from $2,300 2023-10-17
Junos HIGH 7.8
CVE-2023-44194

An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS allows an unauthenticated attacker with local access to the device to cre…

Fix: 20.4+
Fix from $1,950 2023-10-13
Ideapad Creator 5 16ach6 Firmware HIGH 7.8
CVE-2022-3431

A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated …

Mitigation only
Fix from $1,950 2023-10-09
Jp1\/performance Management HIGH 7.8
CVE-2023-3440

Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.This issue affects JP1/Performa…

Mitigation only
Fix from $1,950 2023-10-03
Jboss A Mq MEDIUM 5.5
CVE-2023-4065

A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Opera…

Mitigation only
Fix from $1,600 2023-09-27
Cyber Protect HIGH 7.8
CVE-2023-44157

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 3…

Fix: 15+
Fix from $1,950 2023-09-27
Single Sign On CRITICAL 9.8
CVE-2022-4039

A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This …

Mitigation only
Fix from $2,300 2023-09-22
Mobile Security Framework HIGH 7.5
CVE-2023-42261

Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentio…

Fix: after 3.7.6
Fix from $1,950 2023-09-21
Jenkins HIGH 8.8
CVE-2023-43496

Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly …

Fix: 2.414.2 / 2.424+
Fix from $1,950 2023-09-20
Cyber Protect Home Office HIGH 7.5
CVE-2023-5042

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows)…

Fix: 40713+
Fix from $1,950 2023-09-20
Gx Works3 HIGH 7.8
CVE-2023-4088

Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local att…

Mitigation only
Fix from $1,950 2023-09-20
Cri O MEDIUM 5.3
CVE-2022-3466

The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-20…

Mitigation only
Fix from $1,600 2023-09-15
Connect HIGH 8.8
CVE-2023-4664

Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9.

Fix: 9.0+
Fix from $1,950 2023-09-15
Wing Ftp Server HIGH 8.8
CVE-2023-37878

Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.

Fix: after 7.2.0
Fix from $1,950 2023-09-12
Visiwin 7 HIGH 7.8
CVE-2023-31468

An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\INOSOFT GmbH" folder has weak …

Fix: after 2022-2.1
Fix from $1,950 2023-09-11
Tsplus Remote Access CRITICAL 9.8
CVE-2023-31067

An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAM…

Fix: after 16.0.2.14
Fix from $2,300 2023-09-11
Tsplus Remote Work CRITICAL 9.8
CVE-2023-31068

An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAM…

Fix: after 16.0.0.0
Fix from $2,300 2023-09-11
Ipados MEDIUM 5.3
CVE-2023-34352

A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.4, tvOS 16.5, iOS 16.5 an…

Fix: 9.5 / 13.4+
Fix from $1,600 2023-09-06
Safenet Authentication Service MEDIUM 5.5
CVE-2023-2737

Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via…

Mitigation only
Fix from $1,600 2023-08-16
Powerscale Onefs HIGH 7.1
CVE-2023-32492

Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this…

Fix: after 9.5.0.3
Fix from $1,950 2023-08-16
Mavinci Desktop HIGH 7.8
CVE-2023-32547

Incorrect default permissions in the MAVinci Desktop Software for Intel(R) Falcon 8+ before version 6.2 may allow authenticated user to potentially e…

Fix: 6.2+
Fix from $1,950 2023-08-11
Realsense Software Development Kit HIGH 7.8
CVE-2023-32663

Incorrect default permissions in some Intel(R) RealSense(TM) SDKs in version 2.53.1 may allow an authenticated user to potentially enable escalation …

Fix: after 0.25.0
Fix from $1,950 2023-08-11
Server Debug And Provisioning Tool HIGH 7.8
CVE-2023-31246

Incorrect default permissions in some Intel(R) SDP Tool software before version 1.4 build 5 may allow an authenticated user to potentially enable esc…

Fix: 1.4+
Fix from $1,950 2023-08-11
Intelligent Test System HIGH 7.8
CVE-2023-32543

Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially enable escalation of privile…

Fix: 3.1+
Fix from $1,950 2023-08-11
Advanced Link Analyzer HIGH 7.8
CVE-2023-27505

Incorrect default permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installers before version 22.1 .1 may allow an authen…

Fix: 22.1+
Fix from $1,950 2023-08-11
Arm Compiler HIGH 7.8
CVE-2022-43702

When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installe…

Fix: 6.6.5 / 6.18+
Fix from $1,950 2023-07-27