Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Xampp HIGH 8.8
CVE-2022-29376

Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary …

Fix: after 8.1.4
Fix from $1,950 2022-05-23
Dev C\+\+ HIGH 8.8
CVE-2022-28999

Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binar…

No fix yet
Fix from $1,950 2022-05-23
Dsl G2452dg Firmware CRITICAL 9.8
CVE-2022-28932

D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

Mitigation only
Fix from $2,300 2022-05-23
Cilium HIGH 8.2
CVE-2022-29178

Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Cilium prior to versi…

Fix: 1.9.16 / 1.10.11+
Fix from $1,950 2022-05-20
Fedora HIGH 7.8
CVE-2022-29162

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 wh…

Fix: 1.1.2+
Fix from $1,950 2022-05-17
Deception HIGH 7.8
CVE-2022-0486

Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with loc…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Deception HIGH 7.8
CVE-2022-0997

Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, admin…

Fix: 9.4.5+
Fix from $1,950 2022-05-17
Air Cargo Management System MEDIUM 6.5
CVE-2022-30367

Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.

No fix yet
Fix from $1,600 2022-05-13
Simple Social Networking Site MEDIUM 6.5
CVE-2022-30375

Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img.

No fix yet
Fix from $1,600 2022-05-13
Guru HIGH 7.5
CVE-2022-23802

Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to p…

Mitigation only
Fix from $1,950 2022-05-06
Mahara HIGH 7.5
CVE-2022-29585

In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are …

Fix: 20.10.5 / 21.04.4+
Fix from $1,950 2022-04-28
Webmail Messenger MEDIUM 5.5
CVE-2022-28218

An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configur…

Fix: 4.2.1+
Fix from $1,600 2022-04-26
Pcmanager MEDIUM 5.0
CVE-2021-3722

A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configuration files to be written to…

Fix: 4.0.40.2175+
Fix from $1,600 2022-04-22
Virtualized Infrastructure Manager HIGH 7.8
CVE-2022-20732

A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an authenticated, local attacker …

Fix: 4.2.2+
Fix from $1,950 2022-04-21
Createredirect HIGH 7.5
CVE-2022-29547

The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This c…

Fix: 2022-04-14+
Fix from $1,950 2022-04-21
Roboguide HIGH 7.0
CVE-2021-43986

The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replac…

Fix: after 9.40083.00.05
Fix from $1,950 2022-04-20
Cri O MEDIUM 5.3
CVE-2022-27652

A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker En…

Fix: 20.10.14+
Fix from $1,600 2022-04-18
WordPress MEDIUM 6.5
CVE-2011-1762

A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow…

Fix: 3.0.6 / 3.1.2+
Fix from $1,600 2022-04-18
Android HIGH 7.8
CVE-2021-39794

In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a m…

Mitigation only
Fix from $1,950 2022-04-12
Discourse MEDIUM 5.3
CVE-2022-24804

Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expo…

Fix: 2.8.3+
Fix from $1,600 2022-04-11
Febs Security MEDIUM 5.4
CVE-2022-27958

Insecure permissions configured in the userid parameter at /user/getuserprofile of FEBS-Security v1.0 allows attackers to access and arbitrarily modi…

No fix yet
Fix from $1,600 2022-04-10
Ofcms MEDIUM 5.4
CVE-2022-27960

Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify …

No fix yet
Fix from $1,600 2022-04-10
Emc Powerscale Onefs MEDIUM 5.5
CVE-2022-26855

Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local malicious user could potentially expl…

Fix: after 9.3.0.0
Fix from $1,600 2022-04-08
Control For Beaglebone Sl MEDIUM 6.5
CVE-2022-22518

A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part o…

Fix: 4.5.0.0+
Fix from $1,600 2022-04-07
Developer Tools HIGH 7.5
CVE-2022-27649

A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker E…

Patch available
Fix from $1,950 2022-04-04
Fedora HIGH 7.5
CVE-2022-27650

A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engi…

Fix: 1.4.4+
Fix from $1,950 2022-04-04
Fedora MEDIUM 6.8
CVE-2022-27651

A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) whe…

Fix: 1.25.0+
Fix from $1,600 2022-04-04
Android MEDIUM 5.5
CVE-2021-39769

In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. Thi…

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39770

In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could lead to local information disc…

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39779

In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call stat…

Mitigation only
Fix from $1,600 2022-03-30