Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Illumos HIGH 8.1
CVE-2019-9579

An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended a…

Patch available
Fix from $1,950 2022-12-26
Thunderbird HIGH 7.8
CVE-2022-3155

When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received fil…

Fix: 102.3+
Fix from $1,950 2022-12-22
Firefox HIGH 8.8
CVE-2022-29909

Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing pro…

Fix: 91.9 / 100.0+
Fix from $1,950 2022-12-22
Apiman MEDIUM 6.5
CVE-2022-47551

Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The root cause of the issue is the …

Fix: after 2.2.3
Fix from $1,600 2022-12-20
Android HIGH 7.8
CVE-2022-20611

In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. Th…

Patch available
Fix from $1,950 2022-12-13
Android HIGH 7.8
CVE-2022-20474

In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead…

Patch available
Fix from $1,950 2022-12-13
Android HIGH 7.8
CVE-2022-20475

In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This…

Patch available
Fix from $1,950 2022-12-13
Android HIGH 7.8
CVE-2022-20495

In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in …

Patch available
Fix from $1,950 2022-12-13
Sametime MEDIUM 6.5
CVE-2022-42446

Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Dire…

Mitigation only
Fix from $1,600 2022-12-12
Z1 G3 Firmware HIGH 8.4
CVE-2022-37018

A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code executi…

Fix: 01.33 / 01.85+
Fix from $1,950 2022-12-12
Omen Gaming Hub CRITICAL 9.8
CVE-2021-3437EPSS 16%

Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of se…

Fix: 1.0.44 / 11.6.3.0+
Fix from $2,300 2022-12-12
Jumpstart HIGH 7.8
CVE-2022-1038

A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending th…

Patch available
Fix from $1,950 2022-12-12
Openharmony MEDIUM 5.5
CVE-2022-45118

OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the p…

Fix: after 3.1.4
Fix from $1,600 2022-12-08
Digital Rebar HIGH 8.8
CVE-2022-46382

RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 has Insecure Permissions. Afte…

Fix: after 4.10.8
Fix from $1,950 2022-12-06
Endpoint Manager CRITICAL 9.8
CVE-2022-27773

A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated priv…

Fix: 2021.1+
Fix from $2,300 2022-12-05
Dvg G5402sp Firmware CRITICAL 9.8
CVE-2022-44929

An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profil…

No fix yet
Fix from $2,300 2022-12-02
Omnia Mpx Node Firmware HIGH 8.8
CVE-2022-45562

Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account…

Fix: after 1.4.9
Fix from $1,950 2022-12-02
Labview Command Line Interface HIGH 7.8
CVE-2022-42718

Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially e…

Fix: 22.3.1+
Fix from $1,950 2022-12-01
Aspire A315 22g Firmware HIGH 8.2
CVE-2022-4020

Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secur…

Mitigation only
Fix from $1,950 2022-11-28
Sourcegraph HIGH 7.2
CVE-2022-41943

sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `custom…

Fix: 4.1.0+
Fix from $1,950 2022-11-22
Digital Experience Platform MEDIUM 5.3
CVE-2022-42127

The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, …

Fix: 7.4.3.37+
Fix from $1,600 2022-11-15
Digital Experience Platform MEDIUM 5.3
CVE-2022-42128

The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows rem…

Fix: 7.4.3.5+
Fix from $1,600 2022-11-15
Nuc Kit Wireless Adapter Driver Installer HIGH 7.8
CVE-2022-36377

Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.…

Fix: 22.40.0+
Fix from $1,950 2022-11-11
Harmonyos HIGH 7.5
CVE-2022-44554

The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module …

No fix yet
Fix from $1,950 2022-11-09
Harmonyos HIGH 7.5
CVE-2022-44557

The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation o…

No fix yet
Fix from $1,950 2022-11-09
Emui HIGH 7.5
CVE-2022-44561

The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arb…

Mitigation only
Fix from $1,950 2022-11-09
Expresscluster X CRITICAL 9.8
CVE-2022-34824

Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO …

Fix: after 5.0
Fix from $2,300 2022-11-08
Android HIGH 7.8
CVE-2022-20441

In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to loc…

Mitigation only
Fix from $1,950 2022-11-08
Android MEDIUM 5.5
CVE-2022-20448

In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could…

Mitigation only
Fix from $1,600 2022-11-08
Android HIGH 7.8
CVE-2022-20452

In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to lo…

Mitigation only
Fix from $1,950 2022-11-08