Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Forticlient MEDIUM 5.5
CVE-2022-33877

An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConver…

Fix: after 7.0.6
Fix from $1,600 2023-06-13
Todo Backup HIGH 7.8
CVE-2023-32221

EaseUS Todo Backup version 20220111.390 - An omission during installation may allow a local attacker to perform privilege escalation.

Mitigation only
Fix from $1,950 2023-06-12
Exynos 5123 Firmware CRITICAL 9.8
CVE-2023-31116

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permission can cause unintended quer…

Mitigation only
Fix from $2,300 2023-06-07
Msm CRITICAL 9.8
CVE-2023-33282

Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid sessio…

Fix: after 14.19.0.12476
Fix from $2,300 2023-06-07
Thinkpad Hybrid Usb C With Usb A Dock Firmware HIGH 7.8
CVE-2022-4569

A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local acces…

Fix: 1.0.35_v2+
Fix from $1,950 2023-06-05
Deno Runtime CRITICAL 9.8
CVE-2023-33966

Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` …

Mitigation only
Fix from $2,300 2023-05-31
Download Center HIGH 7.5
CVE-2023-2749

Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access …

Fix: 1.1.5.r1298+
Fix from $1,950 2023-05-31
Solive HIGH 7.5
CVE-2023-29731

SoLive 1.6.14 thru 1.6.20 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage t…

Fix: after 1.6.20
Fix from $1,950 2023-05-30
Solive CRITICAL 9.8
CVE-2023-29732

SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker c…

Fix: after 1.6.20
Fix from $2,300 2023-05-30
Lock Master HIGH 7.8
CVE-2023-29733

The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These files hold data that affects…

No fix yet
Fix from $1,950 2023-05-30
Powerpath HIGH 7.8
CVE-2023-28079

PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability. A regular user (non-admin) can exploit th…

Patch available
Fix from $1,950 2023-05-30
Gs1900 8 Firmware MEDIUM 6.7
CVE-2022-45853

The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could…

Mitigation only
Fix from $1,600 2023-05-30
Nfpm HIGH 7.1
CVE-2023-32698

nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged the files (without extra …

Fix: 2.29.0+
Fix from $1,950 2023-05-30
Ebankit HIGH 7.4
CVE-2023-33291

In ebankIT 6, the public endpoints /public/token/Email/generate and /public/token/SMS/generate allow generation of OTP messages to any e-mail address…

No fix yet
Fix from $1,950 2023-05-28
Solarview Compact Firmware CRITICAL 9.1
CVE-2023-29919EPSS 60%

SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restrict…

Fix: after 6.0
Fix from $2,300 2023-05-23
Allwaysync HIGH 7.8
CVE-2023-29838

Insecure Permission vulnerability found in Botkind/Siber Systems SyncApp v.19.0.3.0 allows a local attacker toe escalate privileges via the SyncServi…

No fix yet
Fix from $1,950 2023-05-22
Emui HIGH 7.5
CVE-2023-1693

The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.

Fix: 3.1.0+
Fix from $1,950 2023-05-20
Pdf Editor HIGH 7.8
CVE-2023-33240

Foxit PDF Reader (12.1.1.15289 and earlier) and Foxit PDF Editor (12.1.1.15289 and all previous 12.x versions, 11.2.5.53785 and all previous 11.x ver…

Fix: after 12.1.1.15289
Fix from $1,950 2023-05-19
Agent HIGH 7.8
CVE-2022-45452

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acron…

Fix: 15+
Fix from $1,950 2023-05-18
Agent HIGH 7.5
CVE-2022-45459

Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 3002…

Fix: 15+
Fix from $1,950 2023-05-18
Scquickaccounting MEDIUM 6.5
CVE-2023-30281

Insecure permissions vulnerability was discovered, due to a lack of permissions’s control in scquickaccounting before v3.7.3 from Store Commander for…

Fix: 3.7.3+
Fix from $1,600 2023-05-16
Android MEDIUM 5.5
CVE-2023-21104

In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution p…

Patch available
Fix from $1,600 2023-05-15
Android HIGH 7.8
CVE-2023-21107

In retrieveAppEntry of NotificationAccessDetails.java, there is a missing permission check. This could lead to local escalation of privilege across u…

Patch available
Fix from $1,950 2023-05-15
Nuc P14e Laptop Element HIGH 7.8
CVE-2023-27382

Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may all…

Fix: 1.0.0.156+
Fix from $1,950 2023-05-10
Setup And Configuration Software HIGH 7.8
CVE-2023-22440

Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potent…

Fix: after 2.1.9
Fix from $1,950 2023-05-10
Nuc P14e Laptop Element HIGH 7.8
CVE-2022-41687

Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may all…

Fix: 1.1.44+
Fix from $1,950 2023-05-10
Nuc Hdmi Firmware Update Tool HIGH 7.8
CVE-2022-40971

Incorrect default permissions for the Intel(R) HDMI Firmware Update Tool for NUC before version 1.79.1.1 may allow an authenticated user to potential…

Fix: 1.79.1.1+
Fix from $1,950 2023-05-10
Nuc Pro Software Suite HIGH 7.8
CVE-2022-36391

Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable es…

Fix: 2.0.0.3+
Fix from $1,950 2023-05-10
Unite HIGH 7.8
CVE-2022-33963

Incorrect default permissions in the software installer for Intel(R) Unite(R) Client software for Windows before version 4.2.34870 may allow an authe…

Fix: 4.2.34870+
Fix from $1,950 2023-05-10
Virtual Raid On Cpu HIGH 7.8
CVE-2022-30338

Incorrect default permissions in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalatio…

Fix: 7.7.6.1003+
Fix from $1,950 2023-05-10