Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Support MEDIUM 5.5
CVE-2022-27500

Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated user to potentially enable info…

Fix: 21.7.40+
Fix from $1,600 2022-08-18
Open Active Management Technology Cloud Toolkit CRITICAL 9.8
CVE-2022-25899

Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated use…

Fix: 2.0.2 / 2.2.2+
Fix from $2,300 2022-08-18
Single Event Api HIGH 7.8
CVE-2022-26344

Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable esca…

Mitigation only
Fix from $1,950 2022-08-18
Connect M MEDIUM 5.5
CVE-2021-44470

Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authenticated user to potentially enab…

Fix: 1.7.4+
Fix from $1,600 2022-08-18
Sterling B2b Integrator MEDIUM 6.5
CVE-2021-39087

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticat…

Fix: 6.0.3.6 / 6.1.0.5+
Fix from $1,600 2022-08-16
Viewpower HIGH 7.8
CVE-2021-30490

upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticate…

Fix: after 1.04-21353
Fix from $1,950 2022-08-16
Android MEDIUM 5.5
CVE-2022-20272

In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could l…

Mitigation only
Fix from $1,600 2022-08-12
Android HIGH 7.8
CVE-2022-20246

In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check…

Mitigation only
Fix from $1,950 2022-08-11
Emui CRITICAL 9.8
CVE-2022-37003

The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauth…

No fix yet
Fix from $2,300 2022-08-10
Emui HIGH 7.5
CVE-2022-37006

Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.

No fix yet
Fix from $1,950 2022-08-10
Gromox HIGH 7.8
CVE-2022-37030

Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a local unprivileged user in the g…

Fix: 1.28+
Fix from $1,950 2022-08-04
Qradar Security Information And Event Manager MEDIUM 5.5
CVE-2022-22424

IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. I…

Fix: 7.3.3 / 7.4.3+
Fix from $1,600 2022-07-20
Emui CRITICAL 9.1
CVE-2022-34737

The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity…

No fix yet
Fix from $2,300 2022-07-12
Android MEDIUM 5.5
CVE-2022-30758

Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with pr…

Mitigation only
Fix from $1,600 2022-07-12
Mattermost Server MEDIUM 5.3
CVE-2022-2366

Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations …

Fix: 6.3.9 / 6.5.2+
Fix from $1,600 2022-07-12
Curl CRITICAL 9.8
CVE-2022-32207EPSS 7%

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from …

Fix: 7.84.0+
Fix from $2,300 2022-07-07
Devolutions Server HIGH 8.8
CVE-2022-33996

Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that …

Fix: 2022.2.0+
Fix from $1,950 2022-07-07
GitLab MEDIUM 5.3
CVE-2022-2270

An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all v…

Fix: 14.10.5 / 15.0.4+
Fix from $1,600 2022-07-01
Cva6 HIGH 7.5
CVE-2022-33023

CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.

Mitigation only
Fix from $1,950 2022-06-29
Ftp Server HIGH 8.8
CVE-2021-41635

When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnera…

No fix yet
Fix from $1,950 2022-06-24
Ftp Server HIGH 7.1
CVE-2021-41637

Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among…

No fix yet
Fix from $1,950 2022-06-24
Amq Broker HIGH 8.8
CVE-2022-1833

A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where th…

Mitigation only
Fix from $1,950 2022-06-21
Checkmk HIGH 7.8
CVE-2022-33912

A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise ed…

Mitigation only
Fix from $1,950 2022-06-17
Couchbase Server HIGH 8.8
CVE-2022-32562

An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.

Fix: after 7.0.4
Fix from $1,950 2022-06-13
Emui MEDIUM 5.3
CVE-2021-46811

HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Productio…

Mitigation only
Fix from $1,600 2022-06-13
Universal Management Suite MEDIUM 5.5
CVE-2022-25804

An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig registry key (under JavaSoft…

No fix yet
Fix from $1,600 2022-06-09
Smartthings MEDIUM 5.5
CVE-2022-30747

PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Inten…

Fix: 1.7.85.25+
Fix from $1,600 2022-06-07
Knime Analytics Platform HIGH 7.8
CVE-2022-31500

In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions.

Fix: 4.6.0+
Fix from $1,950 2022-06-02
E Design HIGH 7.8
CVE-2022-29483

Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating…

Fix: after 1.12.2.0004
Fix from $1,950 2022-06-02
E Design MEDIUM 5.5
CVE-2022-28702

Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating…

Fix: after 1.12.2.0004
Fix from $1,600 2022-06-02