Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Moodle MEDIUM 5.3
CVE-2021-36397

In Moodle, insufficient capability checks meant message deletions were not limited to the current user.

Fix: 3.9.8 / 3.10.5+
Fix from $1,600 2023-03-06
Moodle MEDIUM 5.3
CVE-2021-36400

In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.

Fix: 3.9.8 / 3.10.5+
Fix from $1,600 2023-03-06
We1626 Firmware HIGH 7.5
CVE-2022-45552

An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information …

No fix yet
Fix from $1,950 2023-03-03
Emc Powerscale Onefs HIGH 7.1
CVE-2023-25540

Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerab…

Fix: after 9.4.0.11
Fix from $1,950 2023-02-28
Automation Director HIGH 7.1
CVE-2020-36652

Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infra…

Fix: 10.9.1-00+
Fix from $1,950 2023-02-28
Ops Center Analyzer HIGH 7.1
CVE-2022-3884

Incorrect Default Permissions vulnerability in Hitachi Ops Center Analyzer on Windows (Hitachi Ops Center Analyzer RAID Agent component) allows local…

Fix: 10.9.1-00+
Fix from $1,950 2023-02-28
Lizhifaka HIGH 8.8
CVE-2021-34164

Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function in the admin…

No fix yet
Fix from $1,950 2023-02-17
Ttyd CRITICAL 9.8
CVE-2021-34182

An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.

No fix yet
Fix from $2,300 2023-02-17
Sterling B2b Integrator HIGH 8.8
CVE-2022-40232

IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should no…

Fix: after 6.1.1.1
Fix from $1,950 2023-02-17
Quickassist Technology HIGH 7.8
CVE-2022-36397

Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user t…

Fix: 1.6 / 4.17+
Fix from $1,950 2023-02-16
Xeon Gold 5315y Firmware MEDIUM 6.7
CVE-2022-33196

Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extens…

Mitigation only
Fix from $1,600 2023-02-16
Linux Enterprise Module For Sap Applications HIGH 7.8
CVE-2022-45153

An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux En…

No fix yet
Fix from $1,950 2023-02-15
Agent HIGH 7.5
CVE-2022-45454

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161,…

Mitigation only
Fix from $1,950 2023-02-13
Galaxy Store HIGH 7.8
CVE-2023-21433

Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.

Fix: 4.5.49.8+
Fix from $1,950 2023-02-09
Rmt Server HIGH 7.8
CVE-2022-31254

A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Serv…

Fix: 2.10+
Fix from $1,950 2023-02-07
Support Assistant HIGH 7.8
CVE-2022-23453

Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of in…

Fix: 9.11+
Fix from $1,950 2023-02-01
Support Assistant HIGH 7.8
CVE-2022-23454

Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of in…

Fix: 9.11+
Fix from $1,950 2023-02-01
Emc Powerscale Onefs HIGH 7.8
CVE-2022-45099

Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially…

Fix: 9.1.0.24 / 9.2.1.18+
Fix from $1,950 2023-02-01
Networx HIGH 8.8
CVE-2022-48199

SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges via a low-privileged user ac…

Mitigation only
Fix from $1,950 2023-01-26
Rtf3505vw N1 Firmware HIGH 7.8
CVE-2022-47040

An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running the tcpdump command after pla…

No fix yet
Fix from $1,950 2023-01-26
Ideapad Y700 14isk Firmware MEDIUM 6.7
CVE-2022-3432

A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an at…

Mitigation only
Fix from $1,600 2023-01-26
Android HIGH 7.8
CVE-2022-20456

In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead…

Mitigation only
Fix from $1,950 2023-01-26
D330 10igl Firmware MEDIUM 6.7
CVE-2022-3430

A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify s…

Mitigation only
Fix from $1,600 2023-01-23
Leyun HIGH 7.5
CVE-2022-1109

An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.

Fix: 6.8.21.99+
Fix from $1,950 2023-01-20
Cx Cloud Agent MEDIUM 6.7
CVE-2023-20043

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to …

Fix: 1.9+
Fix from $1,600 2023-01-20
Opentext Extended Ecm HIGH 8.1
CVE-2022-45924

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate2 allows a low-privilege user…

Fix: after 22.3
Fix from $1,950 2023-01-18
Tuning Manager HIGH 7.1
CVE-2020-36611

Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAI…

Fix: 8.8.5-00+
Fix from $1,950 2023-01-17
Axigen Mail Server CRITICAL 9.8
CVE-2023-23566

A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an acc…

Mitigation only
Fix from $2,300 2023-01-13
Emui HIGH 7.5
CVE-2022-46761

The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malic…

Fix: 2.0+
Fix from $1,950 2023-01-06
Jobe CRITICAL 9.8
CVE-2021-4297

A vulnerability has been found in trampgeek jobe up to 1.6.4 and classified as problematic. This vulnerability affects the function runs_post of the …

Fix: 1.6.5+
Fix from $2,300 2023-01-01