Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Emui MEDIUM 5.3
CVE-2021-22475

There is an Improper permission management vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confid…

No fix yet
Fix from $1,600 2021-10-28
Cfengine MEDIUM 5.5
CVE-2021-38379

The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.

Fix: after 3.18.0
Fix from $1,600 2021-10-27
Gestionale Open HIGH 7.8
CVE-2021-37363

An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in bin folder…

No fix yet
Fix from $1,950 2021-10-26
Apex One HIGH 7.8
CVE-2021-42011

An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with es…

Patch available
Fix from $1,950 2021-10-21
Identity Services Engine MEDIUM 6.5
CVE-2021-40123

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with admi…

Fix: after 2.6
Fix from $1,600 2021-10-21
Ux582lr Firmware MEDIUM 6.8
CVE-2021-42055

ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically proximate attacker.

Fix: 303+
Fix from $1,600 2021-10-18
Remote Desktop Manager HIGH 8.8
CVE-2021-42098

An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch cus…

Fix: 2021.2.16+
Fix from $1,950 2021-10-18
Rconfig HIGH 8.8
CVE-2021-29005

Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password …

Mitigation only
Fix from $1,950 2021-10-11
Cp Ansible MEDIUM 5.5
CVE-2021-33923

Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (pri…

Mitigation only
Fix from $1,600 2021-09-29
Nagios Xi CRITICAL 9.8
CVE-2021-36363

Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

Fix: 5.8.5+
Fix from $2,300 2021-09-28
Nagios Xi CRITICAL 9.8
CVE-2021-36365

Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

Fix: 5.8.5+
Fix from $2,300 2021-09-28
Global Vpn Client HIGH 7.8
CVE-2021-20037

SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which …

Fix: after 4.10.5
Fix from $1,950 2021-09-21
Ipados MEDIUM 5.5
CVE-2021-1831

The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may allow shortcuts to acces…

Fix: 14.5+
Fix from $1,600 2021-09-08
Ipados MEDIUM 5.5
CVE-2021-1832

Copied files may not have the expected file permissions. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS …

Fix: 7.4 / 10.15.7+
Fix from $1,600 2021-09-08
macOS MEDIUM 5.5
CVE-2021-30750

The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3. A malicious application may be able to access the…

Fix: 11.3+
Fix from $1,600 2021-09-08
macOS MEDIUM 5.5
CVE-2021-31006

Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 7.6, tvOS 14.7, macOS Big Sur 11.5. A malicio…

Fix: 7.6 / 11.5+
Fix from $1,600 2021-08-24
Ipados MEDIUM 5.5
CVE-2021-31007

Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, tvOS 15.1, macOS Big Sur 11…

Fix: 8.1 / 11.6.2+
Fix from $1,600 2021-08-24
Sn1per HIGH 8.8
CVE-2021-39273

In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify th…

No fix yet
Fix from $1,950 2021-08-19
Sn1per CRITICAL 9.8
CVE-2021-39274

In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user to modify…

No fix yet
Fix from $2,300 2021-08-19
Nagios Xi MEDIUM 5.3
CVE-2021-37351

Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP …

Fix: 5.8.5+
Fix from $1,600 2021-08-13
Amica Prodigy HIGH 7.8
CVE-2021-35312

A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has incorrect permis…

No fix yet
Fix from $1,950 2021-08-06
Linux Agent HIGH 7.8
CVE-2021-36795

A permission issue in the Cohesity Linux agent may allow privilege escalation in version 6.5.1b to 6.5.1d-hotfix10, 6.6.0a to 6.6.0b-hotfix1. An unde…

Fix: after 6.6.0b
Fix from $1,950 2021-08-06
Harmonyos MEDIUM 5.5
CVE-2021-22295

A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to…

Mitigation only
Fix from $1,600 2021-08-06
Apex One HIGH 7.8
CVE-2021-32464

An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security…

Mitigation only
Fix from $1,950 2021-08-04
Digital Experience Platform MEDIUM 6.3
CVE-2021-33333

The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pac…

Fix: 7.3.3+
Fix from $1,600 2021-08-03
Emc Isilon Onefs HIGH 8.8
CVE-2020-5353

The Dell Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 default configuration for Network File System (NFS) allo…

Fix: after 8.2.2
Fix from $1,950 2021-07-29
Emc Isilon Onefs HIGH 8.8
CVE-2020-26180

Dell EMC Isilon OneFS supported versions 8.1 and later and Dell EMC PowerScale OneFS supported version 9.0.0 contain an access issue with the remotes…

Mitigation only
Fix from $1,950 2021-07-28
True Image MEDIUM 6.7
CVE-2020-25593

Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions.

Fix: after 2021
Fix from $1,600 2021-07-15
Android HIGH 7.3
CVE-2021-0441

In onCreate of PermissionActivity.java, there is a possible permission bypass due to Confusing UI. This could lead to local escalation of privilege w…

Patch available
Fix from $1,950 2021-07-14
Android HIGH 7.8
CVE-2021-0486

In onPackageAddedInternal of PermissionManagerService.java, there is possible access to external storage due to a permissions bypass. This could lead…

Patch available
Fix from $1,950 2021-07-14