Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2023-3112 A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to execute co… Ai Virtual Presence Sensor 3.1.50719.1+ Fix from $1,9502023-10-25 CRITICAL 10.0 CVE-2022-42150 TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause Container Es… Cloud Lab Patch available Fix from $2,3002023-10-19 HIGH 7.8 CVE-2023-35183 The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows authenticated users to abuse lo… Access Rights Manager after 2023.2.0.73 Fix from $1,9502023-10-19 HIGH 7.8 CVE-2023-35181 The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows users to abuse incorrect folder… Access Rights Manager after 2023.2.0.73 Fix from $1,9502023-10-19 CRITICAL 9.8 CVE-2023-27133 TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-RemoteWork\Clients\www folder. T… Tsplus Remote Work after 16.0.0.0 Fix from $2,3002023-10-17 HIGH 7.8 CVE-2023-44194 An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS allows an unauthenticated attacker with local access to the device to cre… Junos 20.4+ Fix from $1,9502023-10-13 HIGH 7.8 CVE-2022-3431 A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated … Ideapad Creator 5 16ach6 Firmware Mitigation only Fix from $1,9502023-10-09 HIGH 7.8 CVE-2023-3440 Incorrect Default Permissions vulnerability in Hitachi JP1/Performance Management on Windows allows File Manipulation.This issue affects JP1/Performa… Jp1\/performance Management Mitigation only Fix from $1,9502023-10-03 MEDIUM 5.5 CVE-2023-4065 A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Opera… Jboss A Mq Mitigation only Fix from $1,6002023-09-27 HIGH 7.8 CVE-2023-44157 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 3… Cyber Protect 15+ Fix from $1,9502023-09-27 CRITICAL 9.8 CVE-2022-4039 A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This … Single Sign On Mitigation only Fix from $2,3002023-09-22 HIGH 7.5 CVE-2023-42261 Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentio… Mobile Security Framework after 3.7.6 Fix from $1,9502023-09-21 HIGH 8.8 CVE-2023-43496 Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly … Jenkins 2.414.2 / 2.424+ Fix from $1,9502023-09-20 HIGH 7.5 CVE-2023-5042 Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows)… Cyber Protect Home Office 40713+ Fix from $1,9502023-09-20 HIGH 7.8 CVE-2023-4088 Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local att… Gx Works3 Mitigation only Fix from $1,9502023-09-20 MEDIUM 5.3 CVE-2022-3466 The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-20… Cri O Mitigation only Fix from $1,6002023-09-15 HIGH 8.8 CVE-2023-4664 Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9. Connect 9.0+ Fix from $1,9502023-09-15 HIGH 8.8 CVE-2023-37878 Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0. Wing Ftp Server after 7.2.0 Fix from $1,9502023-09-12 HIGH 7.8 CVE-2023-31468 An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\INOSOFT GmbH" folder has weak … Visiwin 7 after 2022-2.1 Fix from $1,9502023-09-11 CRITICAL 9.8 CVE-2023-31067 An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAM… Tsplus Remote Access after 16.0.2.14 Fix from $2,3002023-09-11 CRITICAL 9.8 CVE-2023-31068 An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAM… Tsplus Remote Work after 16.0.0.0 Fix from $2,3002023-09-11 MEDIUM 5.3 CVE-2023-34352 A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.4, tvOS 16.5, iOS 16.5 an… Ipados 9.5 / 13.4+ Fix from $1,6002023-09-06 MEDIUM 5.5 CVE-2023-2737 Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via… Safenet Authentication Service Mitigation only Fix from $1,6002023-08-16 HIGH 7.1 CVE-2023-32492 Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this… Powerscale Onefs after 9.5.0.3 Fix from $1,9502023-08-16 HIGH 7.8 CVE-2023-32547 Incorrect default permissions in the MAVinci Desktop Software for Intel(R) Falcon 8+ before version 6.2 may allow authenticated user to potentially e… Mavinci Desktop 6.2+ Fix from $1,9502023-08-11 HIGH 7.8 CVE-2023-32663 Incorrect default permissions in some Intel(R) RealSense(TM) SDKs in version 2.53.1 may allow an authenticated user to potentially enable escalation … Realsense Software Development Kit after 0.25.0 Fix from $1,9502023-08-11 HIGH 7.8 CVE-2023-31246 Incorrect default permissions in some Intel(R) SDP Tool software before version 1.4 build 5 may allow an authenticated user to potentially enable esc… Server Debug And Provisioning Tool 1.4+ Fix from $1,9502023-08-11 HIGH 7.8 CVE-2023-32543 Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially enable escalation of privile… Intelligent Test System 3.1+ Fix from $1,9502023-08-11 HIGH 7.8 CVE-2023-27505 Incorrect default permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installers before version 22.1 .1 may allow an authen… Advanced Link Analyzer 22.1+ Fix from $1,9502023-08-11 HIGH 7.8 CVE-2022-43702 When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installe… Arm Compiler 6.6.5 / 6.18+ Fix from $1,9502023-07-27