Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Dameware Mini Remote Control CRITICAL 9.1
CVE-2021-31217

In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.

Mitigation only
Fix from $2,300 2021-07-13
Nextcloud Server MEDIUM 5.3
CVE-2021-32725

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were n…

Fix: 19.0.13 / 20.0.11+
Fix from $1,600 2021-07-12
Ecatcher MEDIUM 6.1
CVE-2021-33214

In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information …

Fix: after 6.6.4
Fix from $1,600 2021-07-09
Ninjarmm HIGH 7.1
CVE-2021-26274

The Agent in NinjaRMM 5.0.909 has Insecure Permissions.

No fix yet
Fix from $1,950 2021-07-07
Emui MEDIUM 5.3
CVE-2021-22346

There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may lead to the disclosu…

Mitigation only
Fix from $1,600 2021-06-30
Emui HIGH 7.5
CVE-2021-22368

There is a Permission Control Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect normal use of the device.

No fix yet
Fix from $1,950 2021-06-30
Emui HIGH 7.5
CVE-2021-22371

There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confi…

No fix yet
Fix from $1,950 2021-06-30
Spectrum Protect Plus MEDIUM 5.5
CVE-2021-20490

IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X…

Fix: after 10.1.8
Fix from $1,600 2021-06-29
Zxv10 B860h V5.0 Firmware HIGH 7.5
CVE-2021-21737

A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attack…

Mitigation only
Fix from $1,950 2021-06-24
Jetson Linux MEDIUM 6.7
CVE-2021-34387

The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserve…

Fix: 32.5.1+
Fix from $1,600 2021-06-21
Brand Verification Tool HIGH 7.8
CVE-2021-0143

Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentia…

Fix: 11.0.0.1225+
Fix from $1,950 2021-06-17
Zxhn Hs562 Firmware HIGH 7.2
CVE-2021-21736

A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cl…

Mitigation only
Fix from $1,950 2021-06-10
Inn HIGH 7.8
CVE-2021-31998

A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE…

Fix: 2.6.2+
Fix from $1,950 2021-06-10
Lapbc510 Firmware HIGH 7.8
CVE-2021-0058

Incorrect default permissions in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to p…

Fix: 1.1+
Fix from $1,950 2021-06-09
Ssd Data Center Tool HIGH 7.8
CVE-2021-0100

Incorrect default permissions in the installer for the Intel(R) SSD Data Center Tool, versions downloaded before 12/31/2020, may allow an authenticat…

Fix: 2020-12-31+
Fix from $1,950 2021-06-09
Ipmctl HIGH 7.8
CVE-2021-0106

Incorrect default permissions in the Intel(R) Optane(TM) DC Persistent Memory for Windows software versions before 2.00.00.3842 or 1.00.00.3515 may a…

Fix: 1.00.00.3515 / 2.00.00.3842+
Fix from $1,950 2021-06-09
Guild Wars 2 HIGH 7.8
CVE-2020-27384

The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated U…

No fix yet
Fix from $1,950 2021-06-09
Licensing Services HIGH 7.8
CVE-2021-27032

Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited privileges could run any number…

Mitigation only
Fix from $1,950 2021-05-28
Coldfusion HIGH 7.8
CVE-2020-10145

The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By …

Mitigation only
Fix from $1,950 2021-05-27
Jitsi Meet HIGH 7.5
CVE-2021-33506

jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This can allow an attacker to circu…

Fix: 2.0.5963+
Fix from $1,950 2021-05-26
Debian Linux HIGH 7.5
CVE-2021-33038

An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, th…

Fix: after 1.3.4
Fix from $1,950 2021-05-26
True Image 2020 HIGH 7.8
CVE-2020-9450

An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe exposes a REST API that can be used by everyone, even unpr…

No fix yet
Fix from $1,950 2021-05-25
True Image 2020 MEDIUM 5.5
CVE-2020-9451

An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where unprivileged users have writ…

No fix yet
Fix from $1,600 2021-05-25
Fusion HIGH 8.8
CVE-2020-28906

Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged…

Fix: after 5.7.5
Fix from $1,950 2021-05-24
Drupal MEDIUM 5.3
CVE-2020-13667

Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't…

Fix: 8.8.10 / 8.9.6+
Fix from $1,600 2021-05-17
Zzcms HIGH 7.5
CVE-2020-21342

Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.

No fix yet
Fix from $1,950 2021-05-13
Housecall For Home Networks HIGH 7.3
CVE-2021-28649

An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an …

Fix: after 5.3.1179
Fix from $1,950 2021-05-12
Housecall For Home Networks HIGH 7.3
CVE-2021-31519

An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could a…

Fix: after 5.3.1179
Fix from $1,950 2021-05-12
Factory HIGH 7.8
CVE-2021-25319

A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to es…

Fix: after 6.1.20-1.1
Fix from $1,950 2021-05-05
Centreon Web MEDIUM 6.5
CVE-2021-26804

Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extens…

Mitigation only
Fix from $1,600 2021-05-04