Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Android HIGH 7.8
CVE-2021-39780

In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could l…

Mitigation only
Fix from $1,950 2022-03-30
Android MEDIUM 5.5
CVE-2021-39747

In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local in…

Mitigation only
Fix from $1,600 2022-03-30
Android MEDIUM 5.5
CVE-2021-39748

In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local in…

Mitigation only
Fix from $1,600 2022-03-30
Android HIGH 7.8
CVE-2021-1000

In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-1033

In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe PendingIntent. This could le…

Mitigation only
Fix from $1,950 2022-03-30
Cloud Foundation MEDIUM 6.5
CVE-2022-22948 KEVEPSS 13%

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative ac…

Fix: 3.11 / 4.4.1+
Fix from $1,600 2022-03-29
Diaenergie HIGH 7.8
CVE-2022-26839

Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which…

Fix: 1.8.02.004+
Fix from $1,950 2022-03-29
Checkmk HIGH 8.8
CVE-2021-40904

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default),…

Fix: 1.6.0+
Fix from $1,950 2022-03-25
Fortessa Ftbtld Firmware HIGH 8.2
CVE-2021-44905

Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attacker to disable the lock via a…

No fix yet
Fix from $1,950 2022-03-25
Enterprise CRITICAL 9.8
CVE-2022-27919

Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configura…

Fix: after 2021.4.3
Fix from $2,300 2022-03-25
Safe MEDIUM 5.3
CVE-2021-44751

A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can tri…

Fix: 18.5+
Fix from $1,600 2022-03-25
Passwordstate MEDIUM 6.5
CVE-2022-25570

In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permission…

No fix yet
Fix from $1,600 2022-03-21
Sa360 Webquery To Bigquery Exporter MEDIUM 5.5
CVE-2021-22571

A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded i…

Fix: 1.0.3+
Fix from $1,600 2022-03-18
Enterprise HIGH 8.1
CVE-2022-25364

In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed…

Fix: 2021.4.2+
Fix from $1,950 2022-03-17
Android HIGH 7.8
CVE-2021-39694

In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. T…

Mitigation only
Fix from $1,950 2022-03-16
Android HIGH 7.8
CVE-2022-25815

PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action wi…

Mitigation only
Fix from $1,950 2022-03-10
Android HIGH 7.8
CVE-2022-25814

PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized ac…

Mitigation only
Fix from $1,950 2022-03-10
Cfengine MEDIUM 5.5
CVE-2021-44216

Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access t…

Fix: 3.15.5 / 3.18.1+
Fix from $1,600 2022-03-10
Cfengine MEDIUM 5.5
CVE-2021-44215

Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.

Fix: 3.15.5 / 3.18.1+
Fix from $1,600 2022-03-10
Emui MEDIUM 6.5
CVE-2021-40059

There is a permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect confidentiality.

No fix yet
Fix from $1,600 2022-03-10
Emui CRITICAL 9.1
CVE-2021-40053

There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.

No fix yet
Fix from $2,300 2022-03-10
Emui HIGH 7.5
CVE-2021-40049

There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information…

No fix yet
Fix from $1,950 2022-03-10
Kexec Tools MEDIUM 5.5
CVE-2021-20269

A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kerne…

Fix: 2.0.20-47 / 2.0.21-8+
Fix from $1,600 2022-03-10
Wps Office HIGH 7.8
CVE-2022-25943

The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service progr…

Fix: 11.2.0.10258+
Fix from $1,950 2022-03-09
Digital Experience Platform MEDIUM 6.5
CVE-2021-38268

The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fi…

Fix: 7.2.1 / 7.3.7+
Fix from $1,600 2022-03-02
Batflat HIGH 7.5
CVE-2021-41652

Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.

Mitigation only
Fix from $1,950 2022-03-01
Emui MEDIUM 5.5
CVE-2021-37103

There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confide…

No fix yet
Fix from $1,600 2022-02-25
Teamcity MEDIUM 6.5
CVE-2022-24337

In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions.

Fix: 2021.2+
Fix from $1,600 2022-02-25
Fscrypt MEDIUM 5.5
CVE-2022-25327

The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other u…

Fix: 0.3.3+
Fix from $1,600 2022-02-25
Win 911 2021 R1 HIGH 7.8
CVE-2022-23104

WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the program Operator Wor…

Mitigation only
Fix from $1,950 2022-02-24