Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Chrome MEDIUM 6.5
CVE-2020-6445

Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy v…

Fix: 81.0.4044.92+
Fix from $1,600 2020-04-13
Chrome MEDIUM 6.5
CVE-2020-6446

Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy v…

Fix: 81.0.4044.92+
Fix from $1,600 2020-04-13
Secdo HIGH 7.8
CVE-2020-1985

Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite system files and gain escala…

Mitigation only
Fix from $1,950 2020-04-08
Android MEDIUM 6.8
CVE-2018-21061

An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) software. A fake charger can execute critical functions in the locked state.…

No fix yet
Fix from $1,600 2020-04-08
Android HIGH 7.5
CVE-2017-18668

An issue was discovered on Samsung mobile devices with M(6.0) software. Attackers can prevent users from making outbound calls and sending outbound t…

No fix yet
Fix from $1,950 2020-04-07
Android HIGH 7.5
CVE-2017-18669

An issue was discovered on Samsung mobile devices with N(7.x) software. Persona has an unprotected API that allows launch of any activity with system…

Mitigation only
Fix from $1,950 2020-04-07
Vbase Editor HIGH 8.8
CVE-2020-7004

VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation …

Mitigation only
Fix from $1,950 2020-04-03
Nexus HIGH 8.8
CVE-2020-11444EPSS 9%

Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.

Fix: after 3.21.2
Fix from $1,950 2020-04-02
Anafi Firmware HIGH 7.5
CVE-2019-3944

Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during…

Fix: 1.5.0+
Fix from $1,950 2020-04-01
Display Control Unit HIGH 8.8
CVE-2020-5551

Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a denial of service attack and/o…

No fix yet
Fix from $1,950 2020-03-30
Pc Worx Srt HIGH 7.8
CVE-2020-10939

Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.

Fix: after 1.14
Fix from $1,950 2020-03-27
Genuine Integrity Service HIGH 7.8
CVE-2020-3766

Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead …

Fix: after 6.4
Fix from $1,950 2020-03-25
Android CRITICAL 9.8
CVE-2019-20536

An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles t…

Mitigation only
Fix from $2,300 2020-03-24
Pricing Table By Supsystic HIGH 7.3
CVE-2020-9392

An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTa…

Fix: 1.8.2+
Fix from $1,950 2020-03-23
Vault MEDIUM 5.3
CVE-2020-10660

HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently i…

Fix: after 1.3.3
Fix from $1,600 2020-03-23
Openitcockpit HIGH 7.5
CVE-2020-10792

openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev"…

Fix: after 3.7.2
Fix from $1,950 2020-03-20
Enigma Network Management Solution HIGH 8.8
CVE-2019-16061

A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing any low p…

Fix: after 65.0.0
Fix from $1,950 2020-03-19
Fortibalancer 400 Firmware HIGH 8.8
CVE-2014-2721

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain p…

Mitigation only
Fix from $1,950 2020-03-19
Fortibalancer 400 Firmware HIGH 8.8
CVE-2014-2722

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain p…

No fix yet
Fix from $1,950 2020-03-19
Fortibalancer 400 Firmware HIGH 8.8
CVE-2014-2723

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain p…

Mitigation only
Fix from $1,950 2020-03-19
Graphics Driver HIGH 7.8
CVE-2020-0508

Incorrect default permissions in the installer for Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.51…

Fix: 15.33.49.5100 / 15.36.38.5117+
Fix from $1,950 2020-03-12
Graphics Driver HIGH 7.8
CVE-2020-0514

Improper default permissions in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7463 and 15.45.30.5103 may allow an authenticat…

Fix: 15.45.30.5103 / 26.20.100.7463+
Fix from $1,950 2020-03-12
Manila HIGH 8.3
CVE-2020-9543

OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, …

Fix: 7.4.1 / 8.1.1+
Fix from $1,950 2020-03-12
Puppet Enterprise HIGH 7.5
CVE-2020-7943EPSS 8%

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things…

Fix: 5.2.15 / 5.3.13+
Fix from $1,950 2020-03-11
Spotfire Analytics Platform For Aws HIGH 8.8
CVE-2020-9408

The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vu…

Fix: after 10.8.0
Fix from $1,950 2020-03-11
Digital Delivery HIGH 7.8
CVE-2020-5342

Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authenticated low-privileged malic…

Fix: 3.5.2015+
Fix from $1,950 2020-03-09
Cyber Security MEDIUM 6.7
CVE-2019-19792

A permissions issue in ESET Cyber Security before 6.8.300.0 for macOS allows a local attacker to escalate privileges by appending data to root-owned …

Fix: 6.8.300.0+
Fix from $1,600 2020-03-03
Ipados HIGH 7.8
CVE-2020-3838

The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, wa…

Fix: 6.1.2 / 10.14.6+
Fix from $1,950 2020-02-27
Couchbase Server CRITICAL 9.8
CVE-2020-9039

Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector an…

Fix: after 4.6.5
Fix from $2,300 2020-02-22
Raid Web Console 3 HIGH 7.8
CVE-2020-0564

Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enabl…

Fix: 7.010.009.000+
Fix from $1,950 2020-02-13