Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2021-36397
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
Moodle
3.9.8 / 3.10.5+
MEDIUM 5.3
CVE-2021-36400
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
Moodle
3.9.8 / 3.10.5+
HIGH 7.5
CVE-2022-45552
An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information …
We1626 Firmware
No fix yet
HIGH 7.1
CVE-2023-25540
Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerab…
Emc Powerscale Onefs
after 9.4.0.11
HIGH 7.1
CVE-2020-36652
Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infra…
Automation Director
10.9.1-00+
HIGH 7.1
CVE-2022-3884
Incorrect Default Permissions vulnerability in Hitachi Ops Center Analyzer on Windows (Hitachi Ops Center Analyzer RAID Agent component) allows local…
Ops Center Analyzer
10.9.1-00+
HIGH 8.8
CVE-2021-34164
Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function in the admin…
Lizhifaka
No fix yet
CRITICAL 9.8
CVE-2021-34182
An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.
Ttyd
No fix yet
HIGH 8.8
CVE-2022-40232
IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should no…
Sterling B2b Integrator
after 6.1.1.1
HIGH 7.8
CVE-2022-36397
Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user t…
Quickassist Technology
1.6 / 4.17+
MEDIUM 6.7
CVE-2022-33196
Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extens…
Xeon Gold 5315y Firmware
Mitigation only
HIGH 7.8
CVE-2022-45153
An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux En…
Linux Enterprise Module For Sap Applications
No fix yet
HIGH 7.5
CVE-2022-45454
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161,…
Agent
Mitigation only
HIGH 7.8
CVE-2023-21433
Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.
Galaxy Store
4.5.49.8+
HIGH 7.8
CVE-2022-31254
A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Serv…
Rmt Server
2.10+
HIGH 7.8
CVE-2022-23453
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of in…
Support Assistant
9.11+
HIGH 7.8
CVE-2022-23454
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of in…
Support Assistant
9.11+
HIGH 7.8
CVE-2022-45099
Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially…
Emc Powerscale Onefs
9.1.0.24 / 9.2.1.18+
HIGH 8.8
CVE-2022-48199
SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges via a low-privileged user ac…
Networx
Mitigation only
HIGH 7.8
CVE-2022-47040
An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running the tcpdump command after pla…
Rtf3505vw N1 Firmware
No fix yet
MEDIUM 6.7
CVE-2022-3432
A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an at…
Ideapad Y700 14isk Firmware
Mitigation only
HIGH 7.8
CVE-2022-20456
In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead…
Android
Mitigation only
MEDIUM 6.7
CVE-2022-3430
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify s…
D330 10igl Firmware
Mitigation only
HIGH 7.5
CVE-2022-1109
An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.
Leyun
6.8.21.99+
MEDIUM 6.7
CVE-2023-20043
A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges.
This vulnerability is due to …
Cx Cloud Agent
1.9+
HIGH 8.1
CVE-2022-45924
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate2 allows a low-privilege user…
Opentext Extended Ecm
after 22.3
HIGH 7.1
CVE-2020-36611
Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAI…
Tuning Manager
8.8.5-00+
CRITICAL 9.8
CVE-2023-23566
A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an acc…
Axigen Mail Server
Mitigation only
HIGH 7.5
CVE-2022-46761
The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malic…
Emui
2.0+
CRITICAL 9.8
CVE-2021-4297
A vulnerability has been found in trampgeek jobe up to 1.6.4 and classified as problematic. This vulnerability affects the function runs_post of the …
Jobe
1.6.5+