Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Active Management Technology Software Development Kit HIGH 7.8
CVE-2020-12354

Incorrect default permissions in Windows(R) installer in Intel(R) AMT SDK versions before 14.0.0.1 may allow an authenticated user to potentially ena…

Fix: 14.0.0.1+
Fix from $1,950 2020-11-12
Endpoint Manager HIGH 7.8
CVE-2020-13770

Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as thes…

Fix: after 2020.1.1
Fix from $1,950 2020-11-12
Realsense D400 Series Dynamic Calibration Tool HIGH 7.8
CVE-2020-12306

Incorrect default permissions in the Intel(R) RealSense(TM) D400 Series Dynamic Calibration Tool before version 2.11, may allow an authenticated user…

Fix: 2.11+
Fix from $1,950 2020-11-12
High Definition Audio Driver HIGH 7.8
CVE-2020-12307

Improper permissions in some Intel(R) High Definition Audio drivers before version 9.21.00.4561 may allow an authenticated user to potentially enable…

Fix: 9.21.00.4561+
Fix from $1,950 2020-11-12
Commerce Cloud MEDIUM 5.3
CVE-2020-26809

SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpo…

No fix yet
Fix from $1,600 2020-11-10
Mxview HIGH 7.8
CVE-2020-13536

An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on t…

No fix yet
Fix from $1,950 2020-11-05
Mxview HIGH 7.8
CVE-2020-13537

An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on t…

No fix yet
Fix from $1,950 2020-11-05
Nighthawk R7000 Firmware MEDIUM 6.5
CVE-2020-28041

The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate with arbitrary TCP and UDP serv…

No fix yet
Fix from $1,600 2020-11-02
Prolinos MEDIUM 6.8
CVE-2020-28044

An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB ser…

Fix: after 2.4.161.8859r
Fix from $1,600 2020-11-02
Mx900 Firmware MEDIUM 6.7
CVE-2019-14718

Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection …

Mitigation only
Fix from $1,600 2020-10-23
Strapi HIGH 7.5
CVE-2020-27665

In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.

Fix: 3.2.5+
Fix from $1,950 2020-10-22
Total Commander HIGH 7.3
CVE-2020-17381

An issue was discovered in Ghisler Total Commander 9.51. Due to insufficient access restrictions in the default installation directory, an attacker c…

No fix yet
Fix from $1,950 2020-10-21
Actfax HIGH 7.3
CVE-2020-15843

ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folder permissions on %PROGRAMFILE…

No fix yet
Fix from $1,950 2020-09-24
Backup \& Replication Director HIGH 7.8
CVE-2020-15850

Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interf…

No fix yet
Fix from $1,950 2020-09-24
Linux Kernel MEDIUM 5.5
CVE-2020-26088

A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create r…

Fix: 5.8.2+
Fix from $1,600 2020-09-24
Android MEDIUM 5.5
CVE-2020-0294

In bindWallpaperComponentLocked of WallpaperManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lea…

Mitigation only
Fix from $1,600 2020-09-18
Android HIGH 7.8
CVE-2020-0374

In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution pr…

Mitigation only
Fix from $1,950 2020-09-17
Android HIGH 7.8
CVE-2020-0275

In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypa…

Mitigation only
Fix from $1,950 2020-09-17
Android HIGH 7.8
CVE-2020-0388

In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permissions bypass due to an empty mutable PendingInten…

Patch available
Fix from $1,950 2020-09-17
Android MEDIUM 5.5
CVE-2020-0390

In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution pri…

Patch available
Fix from $1,600 2020-09-17
System Interface Foundation MEDIUM 5.5
CVE-2020-8346

A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 th…

Fix: 1.1.19.5+
Fix from $1,600 2020-09-15
Simatic Rtls Locating Manager HIGH 7.3
CVE-2020-10049

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The start-stop scripts for the services of the affecte…

Fix: 2.10.2+
Fix from $1,950 2020-09-09
Simatic Rtls Locating Manager HIGH 7.8
CVE-2020-10050

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The directory of service executables of the affected a…

Fix: 2.10.2+
Fix from $1,950 2020-09-09
Eikon HIGH 7.8
CVE-2019-10679

Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFILES(X86)%\Thomson Reuters\Eiko…

No fix yet
Fix from $1,950 2020-09-03
Gmapfp HIGH 7.5
CVE-2020-23971

gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to…

No fix yet
Fix from $1,950 2020-09-01
Django HIGH 7.5
CVE-2020-24583

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMIS…

Fix: 2.2.16 / 3.0.10+
Fix from $1,950 2020-09-01
Django HIGH 7.5
CVE-2020-24584

An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level direc…

Fix: 2.2.16 / 3.0.10+
Fix from $1,950 2020-09-01
Somove HIGH 7.8
CVE-2020-7527

Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access contr…

Fix: after 2.8.1
Fix from $1,950 2020-08-31
Gd32f130 Firmware MEDIUM 6.8
CVE-2020-13468

Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (w…

No fix yet
Fix from $1,600 2020-08-31
Openzfs HIGH 7.8
CVE-2020-24717

OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to…

Fix: after 0.8.4
Fix from $1,950 2020-08-27