Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Robotic Process Automation HIGH 7.5
CVE-2022-43574

"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access …

Fix: 21.0.6+
Fix from $1,950 2022-11-03
Fabric Operating System HIGH 7.8
CVE-2022-33182

A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authent…

Fix: 8.2.3c / 9.0.1e+
Fix from $1,950 2022-10-25
Openshift MEDIUM 5.5
CVE-2013-4281

In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users…

Patch available
Fix from $1,600 2022-10-19
Asusswitch HIGH 7.8
CVE-2022-36438

AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used …

Fix: 1.0.10.0 / 3.1.5.0+
Fix from $1,950 2022-10-18
Asusliveupdate MEDIUM 6.0
CVE-2022-36439

AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp dire…

Fix: 1.0.45.0 / 1.0.53.0+
Fix from $1,600 2022-10-18
Avira Security HIGH 8.8
CVE-2022-3368

A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to e…

Fix: after 1.1.71.30554
Fix from $1,950 2022-10-17
Openharmony HIGH 7.8
CVE-2022-42464

OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. T…

Fix: after 3.1.2
Fix from $1,950 2022-10-14
Jira Align HIGH 8.8
CVE-2022-36803

The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use…

Fix: 10.109.2+
Fix from $1,950 2022-10-14
Gc3 Launch Monitor Firmware HIGH 8.0
CVE-2022-40187

Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all i…

Fix: 1.5.0.2+
Fix from $1,950 2022-10-13
Geodrive HIGH 7.8
CVE-2022-33922

Dell GeoDrive, versions prior to 2.2, contains Insecure File and Folder Permissions vulnerabilities. A low privilege attacker could potentially explo…

Fix: 2.2.3+
Fix from $1,950 2022-10-12
Android HIGH 7.8
CVE-2022-20435

There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission…

Mitigation only
Fix from $1,950 2022-10-11
Android HIGH 7.8
CVE-2022-20436

There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege…

Mitigation only
Fix from $1,950 2022-10-11
Apex One MEDIUM 6.7
CVE-2022-41748

A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with administrative c…

Patch available
Fix from $1,600 2022-10-10
Liferay Portal MEDIUM 5.3
CVE-2022-41414

An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site …

Fix: after 7.4.2
Fix from $1,600 2022-10-07
Remisol Advance HIGH 7.8
CVE-2022-26235

A vulnerability was discovered in the Remisol Advance v2.0.12.1 and below for the Normand Message Server. On installation, the permissions set by Rem…

Fix: after 2.0.12.1
Fix from $1,950 2022-10-06
Scadapro Server HIGH 7.8
CVE-2022-3263

The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileg…

Mitigation only
Fix from $1,950 2022-09-23
Jad Al50 Firmware MEDIUM 5.5
CVE-2021-46834

A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. …

Mitigation only
Fix from $1,600 2022-09-20
Housecall HIGH 7.8
CVE-2022-38764

A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissiv…

Fix: after 1.62.1.1133
Fix from $1,950 2022-09-19
Coreshield One Way Gateway HIGH 7.8
CVE-2022-38466

A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file p…

Fix: 2.2+
Fix from $1,950 2022-09-13
Octopus Server MEDIUM 6.5
CVE-2022-2528

In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages.

Fix: 2022.1.3106 / 2022.2.7718+
Fix from $1,600 2022-09-09
Factory MEDIUM 6.3
CVE-2022-31251

A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over th…

Fix: 22.05.2-3.3+
Fix from $1,600 2022-09-07
Debian Linux HIGH 7.8
CVE-2022-2735

A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between…

Fix: after 0.11.3
Fix from $1,950 2022-09-06
A3002r Firmware CRITICAL 9.8
CVE-2022-40109

TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.

Mitigation only
Fix from $2,300 2022-09-06
Influxdb CRITICAL 9.8
CVE-2022-36640

influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands…

Fix: 1.8.0+
Fix from $2,300 2022-09-02
Fedora HIGH 7.5
CVE-2022-32743

Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.

Fix: 4.17.0+
Fix from $1,950 2022-09-01
Gvim HIGH 7.8
CVE-2022-37173

An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.

Mitigation only
Fix from $1,950 2022-08-30
Fedora HIGH 8.8
CVE-2022-0336

The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the …

Fix: 4.13.17 / 4.14.12+
Fix from $1,950 2022-08-29
Coreos Installer MEDIUM 5.5
CVE-2021-3917

A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw …

Fix: 0.10.0+
Fix from $1,600 2022-08-23
Ansible Runner MEDIUM 6.6
CVE-2021-3701

A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw all…

Patch available
Fix from $1,600 2022-08-23
Mzk Dp150n Firmware HIGH 7.2
CVE-2021-37289

Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web…

No fix yet
Fix from $1,950 2022-08-22