Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Harmonyos HIGH 7.5
CVE-2021-40004

The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality.

Fix: 2.0+
Fix from $1,950 2022-01-10
Emui HIGH 7.5
CVE-2021-39967

There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploi…

Fix: 2.0+
Fix from $1,950 2022-01-03
Harmonyos MEDIUM 5.3
CVE-2021-37132

PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that …

Fix: 2.0+
Fix from $1,600 2022-01-03
Antivirus HIGH 8.8
CVE-2021-45335

Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to control the outcome of scans, an…

Fix: 20.4+
Fix from $1,950 2021-12-27
R Seenet HIGH 7.8
CVE-2021-21911

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A s…

No fix yet
Fix from $1,950 2021-12-22
R Seenet HIGH 7.8
CVE-2021-21912

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A s…

No fix yet
Fix from $1,950 2021-12-22
R Seenet HIGH 7.8
CVE-2021-21910

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A s…

No fix yet
Fix from $1,950 2021-12-22
Mediawiki HIGH 7.5
CVE-2021-44858

An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed …

Fix: 1.35.5 / 1.36.3+
Fix from $1,950 2021-12-20
Android MEDIUM 5.5
CVE-2021-0979

In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests…

Patch available
Fix from $1,600 2021-12-15
Automox HIGH 7.8
CVE-2021-43325

Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression.

Mitigation only
Fix from $1,950 2021-12-15
Automox HIGH 7.8
CVE-2021-43326

Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.

Fix: 32+
Fix from $1,950 2021-12-15
Aws Opensearch CRITICAL 9.8
CVE-2021-44833

The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.

Patch available
Fix from $2,300 2021-12-12
Remote Connector HIGH 7.3
CVE-2021-21957

A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2.16900.0. A specially-crafted…

No fix yet
Fix from $1,950 2021-12-08
Network Access Client HIGH 7.8
CVE-2021-42711

Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This file is executed with SYSTEM pri…

Fix: 5.2.2+
Fix from $1,950 2021-12-01
Tentacle HIGH 7.8
CVE-2021-31822

When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to a local un…

Fix: 6.1.1116+
Fix from $1,950 2021-11-24
Jspwiki CRITICAL 9.1
CVE-2021-44140EPSS 6%

Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http reques…

Fix: 2.11.0+
Fix from $2,300 2021-11-24
Emui HIGH 7.5
CVE-2021-37030

There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

No fix yet
Fix from $1,950 2021-11-23
Vtune Profiler HIGH 7.8
CVE-2021-33062

Incorrect default permissions in the software installer for the Intel(R) VTune(TM) Profiler before version 2021.3.0 may allow an authenticated user t…

Fix: 2021.3.0+
Fix from $1,950 2021-11-17
Oneapi Rendering Toolkit HIGH 7.8
CVE-2021-33071

Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow an authenticated user to pot…

Fix: 2021.2+
Fix from $1,950 2021-11-17
Thunderbolt Non Dch Driver HIGH 7.8
CVE-2020-8741

Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to p…

Mitigation only
Fix from $1,950 2021-11-17
Ax210 Firmware HIGH 7.8
CVE-2021-0065

Incorrect default permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated …

Fix: 22.40+
Fix from $1,950 2021-11-17
Nuc M15 Laptop Kit Integrated Sensor Hub Driver Pack HIGH 7.8
CVE-2021-33088

Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit Integrated Sensor Hub driver pack before version 5.4.1.4449 may al…

Fix: 5.4.1.4449+
Fix from $1,950 2021-11-17
Nuc Hdmi Firmware Update Tool HIGH 7.8
CVE-2021-33090

Incorrect default permissionsin the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC10i3FN, NUC10i5FN, NUC10i7FN before vers…

Fix: 1.78.2.0.7+
Fix from $1,950 2021-11-17
Nuc M15 Laptop Kit Hid Event Filter Driver Pack HIGH 7.8
CVE-2021-33092

Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit HID Event Filter driver pack before version 2.2.1.383 may allow an…

Fix: 2.2.1.383+
Fix from $1,950 2021-11-17
Legion Phone Pro \(l79031\)firmware MEDIUM 5.5
CVE-2021-3720

An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) th…

Fix: 12.5.231 / 12.5.632+
Fix from $1,600 2021-11-12
Teamcity MEDIUM 5.3
CVE-2021-43199

In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.

Fix: 2021.1.2.+
Fix from $1,600 2021-11-09
Dialink HIGH 7.8
CVE-2021-38420

Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow …

Fix: after 1.2.4.0
Fix from $1,950 2021-11-03
Endpoint Security Tools HIGH 7.8
CVE-2021-3579

Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security T…

Fix: 7.2.1.65+
Fix from $1,950 2021-10-28
Emui CRITICAL 9.8
CVE-2021-36989

There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.

No fix yet
Fix from $2,300 2021-10-28
Emui CRITICAL 9.8
CVE-2021-36990

There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.

No fix yet
Fix from $2,300 2021-10-28