Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
macOS MEDIUM 5.5
CVE-2023-28192

A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A…

Fix: 11.7.5 / 12.6.4+
Fix from $1,600 2023-05-08
Gv Edge Recording Manager CRITICAL 9.8
CVE-2023-23059

An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installati…

Mitigation only
Fix from $2,300 2023-05-04
Rancher CRITICAL 9.9
CVE-2023-22651

Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook…

Fix: after 2.7.2
Fix from $2,300 2023-05-04
Nginx Api Connectivity Manager HIGH 7.1
CVE-2023-28724

NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance M…

Fix: 1.3.0 / 1.5.0+
Fix from $1,950 2023-05-03
One Nds HIGH 8.8
CVE-2022-30759

In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and…

Fix: after 20.9
Fix from $1,950 2023-05-02
Download Manager HIGH 7.5
CVE-2023-1809

The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowing attackers to download arbit…

Fix: 6.3.0+
Fix from $1,950 2023-05-02
Obsidian HIGH 7.5
CVE-2023-27035

An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts v…

No fix yet
Fix from $1,950 2023-05-01
System Update HIGH 7.0
CVE-2022-4568

A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.

Fix: 5.08.01.0005+
Fix from $1,950 2023-05-01
Thinkagile Hx5530 Firmware HIGH 8.8
CVE-2023-29057

A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privile…

Fix: 2.93_afbt30p / 3.72_tei388s+
Fix from $1,950 2023-04-28
Thinkagile Hx5530 Firmware MEDIUM 6.5
CVE-2023-29058

A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through …

Fix: 2.93_afbt30p / 3.72_tei388s+
Fix from $1,600 2023-04-28
Sage 300 HIGH 7.8
CVE-2022-38583

On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a l…

Fix: after 2022
Fix from $1,950 2023-04-28
Odoo HIGH 8.7
CVE-2021-23166

A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write loca…

Fix: after 15.0
Fix from $1,950 2023-04-25
One Network Directory Server HIGH 7.8
CVE-2022-31244

Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.

No fix yet
Fix from $1,950 2023-04-25
Powerjob MEDIUM 5.3
CVE-2023-29923EPSS 10%

PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface.

No fix yet
Fix from $1,600 2023-04-19
Mor1kx Firmware HIGH 7.8
CVE-2021-41614

An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The read/write access permissions to the Exception Program Counter R…

Mitigation only
Fix from $1,950 2023-04-18
Junos Os Evolved HIGH 7.8
CVE-2023-28966

An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS Evolved allows a low-privileged local attacker with shell access to modif…

Fix: 20.4+
Fix from $1,950 2023-04-17
Lock Master HIGH 7.1
CVE-2023-27647

An issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the com.ludash…

No fix yet
Fix from $1,950 2023-04-14
File Replication Pro CRITICAL 9.8
CVE-2023-26918EPSS 6%

Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed a…

No fix yet
Fix from $2,300 2023-04-14
Cloud HIGH 8.8
CVE-2023-22951

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. It creates an authentication token for internal systems use. This token can be rea…

No fix yet
Fix from $1,950 2023-04-13
Trusted Device Agent HIGH 7.8
CVE-2023-25542

Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker …

Fix: 5.3.0+
Fix from $1,950 2023-04-06
Fluentd HIGH 8.8
CVE-2020-21514

An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.

No fix yet
Fix from $1,950 2023-04-04
Sipxcom HIGH 8.8
CVE-2023-25355

CoreDial sipXcom up to and including 21.04 is vulnerable to Insecure Permissions. A user who has the ability to run commands as the `daemon` user on …

Fix: after 21.04
Fix from $1,950 2023-04-04
Emc Powerscale Onefs HIGH 7.8
CVE-2023-25941

Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially explo…

Fix: 9.2.1.22 / 9.4.0.13+
Fix from $1,950 2023-04-04
Virtual Gpu HIGH 7.1
CVE-2023-0181

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly c…

Fix: 11.12 / 13.7+
Fix from $1,950 2023-04-01
Emui HIGH 7.5
CVE-2022-48360

The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confidentialit…

Mitigation only
Fix from $1,950 2023-03-27
Openstack MEDIUM 5.5
CVE-2022-3146

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Openstack MEDIUM 5.5
CVE-2022-3101

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Cilium MEDIUM 5.5
CVE-2023-27593

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, an attacker…

Fix: 1.11.15 / 1.12.8+
Fix from $1,600 2023-03-17
Manage Application MEDIUM 6.5
CVE-2022-46774

IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to …

Mitigation only
Fix from $1,600 2023-03-15
GitLab MEDIUM 5.4
CVE-2022-3758

An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all ve…

Fix: 15.7.8 / 15.8.4+
Fix from $1,600 2023-03-09