Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Arm Compiler HIGH 7.8
CVE-2022-43701

When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory t…

Fix: 6.20+
Fix from $1,950 2023-07-27
Roomcast Ta 2400 Firmware CRITICAL 9.8
CVE-2023-33745

TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available after an adb connection, simply e…

Fix: after 3.1
Fix from $2,300 2023-07-27
Ipados HIGH 7.8
CVE-2023-38410

The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. A user may be able to elevate priv…

Fix: 13.5 / 16.6+
Fix from $1,950 2023-07-27
Atera HIGH 7.8
CVE-2023-26077

Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.

Fix: 1.8.3.7+
Fix from $1,950 2023-07-24
Zenon MEDIUM 5.4
CVE-2023-3323

A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker coul…

Fix: after 11.0.0
Fix from $1,600 2023-07-24
Studio MEDIUM 6.5
CVE-2023-38334

Omnis Studio 10.22.00 has incorrect access control. It advertises an irreversible feature for locking classes within Omnis libraries: it should be no…

No fix yet
Fix from $1,600 2023-07-20
Studio MEDIUM 5.3
CVE-2023-38335

Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an i…

No fix yet
Fix from $1,600 2023-07-20
Gg HIGH 8.8
CVE-2023-31462

An issue was discovered in SteelSeries GG 36.0.0. An attacker can change values in an unencrypted database that is writable for all users on the comp…

No fix yet
Fix from $1,950 2023-07-20
Compute Systems Manager HIGH 7.8
CVE-2020-36695

Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitachi Tiered Storage Manager on L…

Fix: 8.8.3-08 / 8.8.5-02+
Fix from $1,950 2023-07-18
Simatic Cn 4100 Firmware CRITICAL 10.0
CVE-2023-29131

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the SSH confi…

Fix: 2.5+
Fix from $2,300 2023-07-11
Tumbleweed HIGH 7.8
CVE-2023-32183

Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hacluster to escalate to root Th…

No fix yet
Fix from $1,950 2023-07-07
Android MEDIUM 6.8
CVE-2023-21513

Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in w…

Mitigation only
Fix from $1,600 2023-06-28
Android HIGH 7.8
CVE-2023-21187

In onCreate of UsbAccessoryUriActivity.java, there is a possible way to escape the Setup Wizard due to a logic error in the code. This could lead to …

Mitigation only
Fix from $1,950 2023-06-28
Android HIGH 7.8
CVE-2023-21175

In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due to a permissions bypass. This …

Mitigation only
Fix from $1,950 2023-06-28
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2023-20178EPSS 5%

A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Win…

Fix: 4.10.07061 / 5.0.02075+
Fix from $1,950 2023-06-28
Apex One MEDIUM 5.5
CVE-2023-30902

A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to unintentionally dele…

Fix: 14.0.12105+
Fix from $1,600 2023-06-26
Ipados MEDIUM 5.5
CVE-2023-32404

This issue was addressed with improved entitlements. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. An app may be …

Fix: 9.5 / 13.4+
Fix from $1,600 2023-06-23
macOS HIGH 7.8
CVE-2023-32405

A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may …

Fix: 11.7.7 / 12.6.6+
Fix from $1,950 2023-06-23
Ipados MEDIUM 5.5
CVE-2023-32407

A logic issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS …

Fix: 9.5 / 11.7.7+
Fix from $1,600 2023-06-23
Ipados MEDIUM 5.5
CVE-2023-32399

The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4…

Fix: 9.5 / 13.4+
Fix from $1,600 2023-06-23
Itunes HIGH 7.8
CVE-2023-32351

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to gain elevated privileges.

Fix: 12.12.9+
Fix from $1,950 2023-06-23
Bigfix Webui Insights MEDIUM 6.5
CVE-2023-23344

A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.

Mitigation only
Fix from $1,600 2023-06-23
Sgi Uv 300 Rmc Firmware HIGH 7.8
CVE-2023-30905

The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced privilege.

Fix: after 1.2.7
Fix from $1,950 2023-06-16
Up T2 4k Firmware HIGH 7.7
CVE-2023-25645

There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application ca…

Mitigation only
Fix from $1,950 2023-06-16
Android HIGH 7.8
CVE-2023-21138

In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input validation. This could lead to loc…

Patch available
Fix from $1,950 2023-06-15
Android HIGH 7.8
CVE-2023-21139

In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. This could lead to local escala…

Patch available
Fix from $1,950 2023-06-15
Android HIGH 7.8
CVE-2023-21121

In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connected VPN due to improper input …

Mitigation only
Fix from $1,950 2023-06-15
Android HIGH 7.8
CVE-2023-21126

In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under SysUI due to Unsafe Intent. Th…

Patch available
Fix from $1,950 2023-06-15
Android HIGH 7.8
CVE-2023-21128

In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a logic error in the code. This co…

Patch available
Fix from $1,950 2023-06-15
Android HIGH 7.8
CVE-2023-21129

In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while the app is in the background…

Mitigation only
Fix from $1,950 2023-06-15