Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Pcmanager MEDIUM 5.5
CVE-2021-3451

A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to be written…

Fix: 3.0.400.3252+
Fix from $1,600 2021-04-27
701clientsql HIGH 8.8
CVE-2021-28271

Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user to change t…

Fix: 10.2+
Fix from $1,950 2021-04-27
Spectrum Protect Backup Archive Client HIGH 7.8
CVE-2021-20532

IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 could allow a local user to escalate their privileges to take full control of the system due to …

Fix: after 8.1.11.0
Fix from $1,950 2021-04-26
Junos HIGH 7.3
CVE-2021-0246

On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, devices using tenant services on Juniper Networks Junos OS, due to incorrect de…

Mitigation only
Fix from $1,950 2021-04-22
Junos HIGH 7.3
CVE-2021-0235

On SRX1500, SRX4100, SRX4200, SRX4600, SRX5000 Series with SPC2/SPC3, vSRX Series devices using tenant services on Juniper Networks Junos OS, due to …

Mitigation only
Fix from $1,950 2021-04-22
Openvpn HIGH 7.5
CVE-2020-27569

Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be lev…

Fix: after 2.8.2
Fix from $1,950 2021-04-21
Synapse MEDIUM 5.5
CVE-2021-30493

Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast s…

No fix yet
Fix from $1,600 2021-04-14
Synapse MEDIUM 5.5
CVE-2021-30494

Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK …

No fix yet
Fix from $1,600 2021-04-14
Power Management Driver HIGH 7.8
CVE-2021-3462

A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized acc…

Fix: 1.67.17.54+
Fix from $1,950 2021-04-13
Openclinic Ga HIGH 7.8
CVE-2020-27228

An incorrect default permissions vulnerability exists in the installation functionality of OpenClinic GA 5.173.3. Overwriting the binary can result i…

No fix yet
Fix from $1,950 2021-04-13
Account HIGH 7.8
CVE-2021-25381

Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows loca…

Mitigation only
Fix from $1,950 2021-04-09
Dream Report HIGH 7.8
CVE-2020-13532

A privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service binary ca…

No fix yet
Fix from $1,950 2021-04-09
Dream Report HIGH 7.8
CVE-2020-13533

A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference bina…

No fix yet
Fix from $1,950 2021-04-09
Dream Report HIGH 7.8
CVE-2020-13534

A privilege escalation vulnerability exists in Dream Report 5 R20-2. COM Class Identifiers (CLSID), installed by Dream Report 5 20-2, reference Local…

No fix yet
Fix from $1,950 2021-04-09
Exposure Notifications Verification Server HIGH 8.8
CVE-2021-22538

A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker wh…

Fix: 0.23.1+
Fix from $1,950 2021-03-31
Vision Pro CRITICAL 9.8
CVE-2021-27193

Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read…

Fix: after 9.7.1
Fix from $2,300 2021-03-25
Notes HIGH 7.8
CVE-2021-25355

Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking th…

Fix: 4.2.00.22+
Fix from $1,950 2021-03-25
Manageone HIGH 7.2
CVE-2021-22311

There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a …

Mitigation only
Fix from $1,950 2021-03-22
Android MEDIUM 5.5
CVE-2021-0381

In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to …

Patch available
Fix from $1,600 2021-03-10
Pcmanager MEDIUM 5.5
CVE-2020-8357

A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written…

Fix: 3.0.200.2042+
Fix from $1,600 2021-03-09
Zstandard MEDIUM 5.5
CVE-2021-24031

In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the inp…

Fix: 1.4.1+
Fix from $1,600 2021-03-04
Webaccess\/scada HIGH 7.8
CVE-2020-13554

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webv…

No fix yet
Fix from $1,950 2021-03-03
Tasks MEDIUM 6.8
CVE-2020-22475

"Tasks" application version before 9.7.3 is affected by insecure permissions. The VoiceCommandActivity application component allows arbitrary applica…

Fix: 9.7.3+
Fix from $1,600 2021-02-22
Xlreporter HIGH 7.8
CVE-2020-13549

An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install directory. Dependi…

No fix yet
Fix from $1,950 2021-02-19
Bitbucket HIGH 7.8
CVE-2020-36233

The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before…

Fix: 6.10.9 / 7.6.4+
Fix from $1,950 2021-02-18
Webaccess\/scada HIGH 8.8
CVE-2020-13551

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In priv…

No fix yet
Fix from $1,950 2021-02-17
Webaccess\/scada HIGH 8.8
CVE-2020-13552

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In priv…

No fix yet
Fix from $1,950 2021-02-17
Webaccess\/scada HIGH 8.8
CVE-2020-13553

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webv…

No fix yet
Fix from $1,950 2021-02-17
Webaccess\/scada HIGH 8.8
CVE-2020-13555

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM …

No fix yet
Fix from $1,950 2021-02-17
Realsense Depth Camera Manager MEDIUM 6.7
CVE-2020-8765

Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a privileged user to potentially enable escalation of pri…

Fix: 1.5 / 2.2+
Fix from $1,600 2021-02-17