Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Solid State Drive Toolbox MEDIUM 6.7
CVE-2020-8701

Incorrect default permissions in installer for the Intel(R) SSD Toolbox versions before 2/9/2021 may allow a privileged user to potentially enable es…

Fix: 2021-02-09+
Fix from $1,600 2021-02-17
Ethernet Controller I210 Firmware MEDIUM 5.5
CVE-2020-0524

Improper default permissions in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow an au…

Fix: 3.30+
Fix from $1,600 2021-02-17
Csdj B Firmware MEDIUM 5.3
CVE-2021-20653

Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and earlier, and CSDJ-A 03.08.00 and earlier) allows remote at…

Fix: after 03.08.00
Fix from $1,600 2021-02-17
Simaris Configuration HIGH 7.8
CVE-2020-28392

A vulnerability has been identified in SIMARIS configuration (All versions < V4.0.1). During installation to default target folder, incorrect permiss…

Fix: 4.0.1+
Fix from $1,950 2021-02-09
Files Antivirus MEDIUM 5.7
CVE-2020-16144

When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and ano…

Fix: 0.15.2+
Fix from $1,600 2021-02-09
Digsi 4 HIGH 7.8
CVE-2020-25245

A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writeable by normal users. As these…

Fix: 4.94+
Fix from $1,950 2021-02-09
Millewin HIGH 8.8
CVE-2021-3394EPSS 6%

Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious…

No fix yet
Fix from $1,950 2021-02-09
Youtrack MEDIUM 5.3
CVE-2020-25208

In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions.

Fix: 2020.4.4701+
Fix from $1,600 2021-02-03
Kotlin MEDIUM 5.3
CVE-2020-29582

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such…

Fix: 2.1.0+
Fix from $1,600 2021-02-03
Q90 Junior Gps Horloge Firmware CRITICAL 9.8
CVE-2019-20468

An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permissions such as READ_EXTERNAL_…

Mitigation only
Fix from $2,300 2021-02-01
Endpoint Antivirus MEDIUM 5.5
CVE-2020-26941

A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file vi…

Fix: after 13.2
Fix from $1,600 2021-01-26
Dolphinscheduler MEDIUM 6.5
CVE-2020-13922

Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter…

Mitigation only
Fix from $1,600 2021-01-11
Debian Linux HIGH 7.1
CVE-2021-1056

NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely hono…

Fix: 390.141 / 450.102.04+
Fix from $1,950 2021-01-08
Gotenberg CRITICAL 9.8
CVE-2020-13452

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can…

Fix: after 6.2.1
Fix from $2,300 2021-01-07
Emc Unity Operating Environment MEDIUM 6.7
CVE-2020-29489

Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (incl…

Fix: 5.0.4.0.5.012+
Fix from $1,600 2021-01-05
Win 911 HIGH 7.8
CVE-2020-13539

An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via…

No fix yet
Fix from $1,950 2021-01-05
Win 911 HIGH 7.8
CVE-2020-13540

An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via…

No fix yet
Fix from $1,950 2021-01-05
Mobile 911 Server HIGH 8.8
CVE-2020-13541

An exploitable local privilege elevation vulnerability exists in the file system permissions of the Mobile-911 Server V2.5 install directory. Dependi…

No fix yet
Fix from $1,950 2021-01-05
Wyse Thinos HIGH 8.6
CVE-2020-29491

Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially …

Fix: after 8.6
Fix from $1,950 2021-01-04
Wyse Thinos CRITICAL 10.0
CVE-2020-29492

Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially …

Fix: after 8.6
Fix from $2,300 2021-01-04
Linkmaster HIGH 7.8
CVE-2020-13535

A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker can globally overwrite service …

No fix yet
Fix from $1,950 2020-12-18
Android HIGH 7.8
CVE-2020-0486

In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local …

Patch available
Fix from $1,950 2020-12-15
Insync HIGH 7.8
CVE-2020-5798

inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user du…

No fix yet
Fix from $1,950 2020-12-07
Logicaldoc HIGH 7.8
CVE-2020-13542

A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an …

No fix yet
Fix from $1,950 2020-12-03
Head Unit Firmware HIGH 7.8
CVE-2020-8539

Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized c…

No fix yet
Fix from $1,950 2020-12-01
Twincat Extended Automation Runtime HIGH 7.3
CVE-2020-12510

The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and furthe…

Mitigation only
Fix from $1,950 2020-11-19
GitLab MEDIUM 6.5
CVE-2020-13351

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pip…

Fix: 13.3.9 / 13.4.5+
Fix from $1,600 2020-11-17
Battery Life Diagnostic Tool HIGH 7.8
CVE-2020-12346

Improper permissions in the installer for the Intel(R) Battery Life Diagnostic Tool before version 1.0.7 may allow an authenticated user to potential…

Fix: 1.0.7+
Fix from $1,950 2020-11-12
Board Id Tool HIGH 7.8
CVE-2020-24456

Incorrect default permissions in the Intel(R) Board ID Tool version v.1.01 may allow an authenticated user to potentially enable escalation of privil…

Mitigation only
Fix from $1,950 2020-11-12
Driver \& Support Assistant MEDIUM 5.5
CVE-2020-24460

Incorrect default permissions in the Intel(R) DSA before version 20.8.30.6 may allow an authenticated user to potentially enable denial of service vi…

Fix: 20.8.30.6+
Fix from $1,600 2020-11-12