Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Win 911 2021 R1 HIGH 7.8
CVE-2022-23922

WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the Program Announcer di…

Mitigation only
Fix from $1,950 2022-02-24
Fedora HIGH 7.1
CVE-2021-45083

An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that…

Fix: 3.3.1+
Fix from $1,950 2022-02-20
Migration Toolkit MEDIUM 6.3
CVE-2021-3948

An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be ab…

Fix: 1.5.2 / 1.6.3+
Fix from $1,600 2022-02-18
Snapd MEDIUM 5.5
CVE-2021-3155

snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local atta…

Fix: 2.54.3+
Fix from $1,600 2022-02-17
Debian Linux CRITICAL 9.8
CVE-2021-20001

It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions…

Fix: 2.12.16+
Fix from $2,300 2022-02-11
Android CRITICAL 9.1
CVE-2021-39635

ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No ph…

Mitigation only
Fix from $2,300 2022-02-11
Android CRITICAL 9.8
CVE-2021-39658

ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions o…

Mitigation only
Fix from $2,300 2022-02-11
C Controller Interface Module Utility CRITICAL 9.8
CVE-2020-14521

Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker cou…

Fix: after 3.42u
Fix from $2,300 2022-02-11
Quartus Prime HIGH 7.8
CVE-2022-21204

Improper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation o…

Fix: 21.3+
Fix from $1,950 2022-02-09
Advisor HIGH 7.8
CVE-2021-33129

Incorrect default permissions in the software installer for the Intel(R) Advisor before version 2021.4.0 may allow an authenticated user to potential…

Fix: 2021.4.0+
Fix from $1,950 2022-02-09
Retail Experience Tool MEDIUM 5.5
CVE-2021-33166

Incorrect default permissions for the Intel(R) RXT for Chromebook application, all versions, may allow an authenticated user to potentially enable in…

Mitigation only
Fix from $1,600 2022-02-09
Hmibmuhi29d2801 Firmware HIGH 7.8
CVE-2021-22817

A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to loca…

Mitigation only
Fix from $1,950 2022-02-09
Agent HIGH 7.8
CVE-2022-24113

Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (W…

Mitigation only
Fix from $1,950 2022-02-04
Debian Linux MEDIUM 6.5
CVE-2022-24301

In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.

Fix: 5.4.0+
Fix from $1,600 2022-02-02
Elite Cms CRITICAL 9.8
CVE-2021-46093

eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.

No fix yet
Fix from $2,300 2022-02-01
Rlc 410w Firmware HIGH 8.8
CVE-2021-40416

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. Al…

No fix yet
Fix from $1,950 2022-01-28
Sq Manager HIGH 8.8
CVE-2021-40388

A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system to escalate …

No fix yet
Fix from $1,950 2022-01-28
Deviceon\/iedge HIGH 8.8
CVE-2021-40389

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in…

No fix yet
Fix from $1,950 2022-01-28
Deviceon\/iservice HIGH 8.8
CVE-2021-40396

A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the…

No fix yet
Fix from $1,950 2022-01-28
Wise Paas\/ota HIGH 7.8
CVE-2021-40397

A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-crafted file can be replaced in …

No fix yet
Fix from $1,950 2022-01-28
Rlc 410w Firmware HIGH 7.1
CVE-2021-40413

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. Th…

No fix yet
Fix from $1,950 2022-01-28
Rlc 410w Firmware HIGH 7.1
CVE-2021-40414

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. Th…

No fix yet
Fix from $1,950 2022-01-28
Rlc 410w Firmware MEDIUM 6.5
CVE-2021-40415

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. In…

No fix yet
Fix from $1,600 2022-01-28
Nextcloud MEDIUM 5.3
CVE-2021-41166

The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to …

Fix: 3.17.1+
Fix from $1,600 2022-01-26
Oneblog MEDIUM 6.5
CVE-2021-46085

OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond their authority.

Fix: after 2.2.8
Fix from $1,600 2022-01-25
Xzs Mysql HIGH 7.5
CVE-2021-46086

xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsa…

No fix yet
Fix from $1,950 2022-01-25
Hospital\'s Patient Records Management System MEDIUM 5.3
CVE-2022-22296

Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id parameter in manage_user endpoint. S…

Mitigation only
Fix from $1,600 2022-01-24
Debian Linux MEDIUM 5.5
CVE-2022-21704

log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile ap…

Fix: 6.4.0+
Fix from $1,600 2022-01-19
Fedora HIGH 8.6
CVE-2021-43860

Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the…

Fix: 1.10.6+
Fix from $1,950 2022-01-12
Laundry Booking Management System CRITICAL 9.8
CVE-2021-45003

Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php throu…

No fix yet
Fix from $2,300 2022-01-10