Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
MEDIUM 5.3 CVE-2021-36397 In Moodle, insufficient capability checks meant message deletions were not limited to the current user. Moodle 3.9.8 / 3.10.5+ Fix from $1,6002023-03-06 MEDIUM 5.3 CVE-2021-36400 In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. Moodle 3.9.8 / 3.10.5+ Fix from $1,6002023-03-06 HIGH 7.5 CVE-2022-45552 An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to obtain sensitive information … We1626 Firmware No fix yet Fix from $1,9502023-03-03 HIGH 7.1 CVE-2023-25540 Dell PowerScale OneFS 9.4.0.x contains an incorrect default permissions vulnerability. A local malicious user could potentially exploit this vulnerab… Emc Powerscale Onefs after 9.4.0.11 Fix from $1,9502023-02-28 HIGH 7.1 CVE-2020-36652 Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infra… Automation Director 10.9.1-00+ Fix from $1,9502023-02-28 HIGH 7.1 CVE-2022-3884 Incorrect Default Permissions vulnerability in Hitachi Ops Center Analyzer on Windows (Hitachi Ops Center Analyzer RAID Agent component) allows local… Ops Center Analyzer 10.9.1-00+ Fix from $1,9502023-02-28 HIGH 8.8 CVE-2021-34164 Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function in the admin… Lizhifaka No fix yet Fix from $1,9502023-02-17 CRITICAL 9.8 CVE-2021-34182 An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions. Ttyd No fix yet Fix from $2,3002023-02-17 HIGH 8.8 CVE-2022-40232 IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to perform actions they should no… Sterling B2b Integrator after 6.1.1.1 Fix from $1,9502023-02-17 HIGH 7.8 CVE-2022-36397 Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user t… Quickassist Technology 1.6 / 4.17+ Fix from $1,9502023-02-16 MEDIUM 6.7 CVE-2022-33196 Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extens… Xeon Gold 5315y Firmware Mitigation only Fix from $1,6002023-02-16 HIGH 7.8 CVE-2022-45153 An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux En… Linux Enterprise Module For Sap Applications No fix yet Fix from $1,9502023-02-15 HIGH 7.5 CVE-2022-45454 Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30161,… Agent Mitigation only Fix from $1,9502023-02-13 HIGH 7.8 CVE-2023-21433 Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store. Galaxy Store 4.5.49.8+ Fix from $1,9502023-02-09 HIGH 7.8 CVE-2022-31254 A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Serv… Rmt Server 2.10+ Fix from $1,9502023-02-07 HIGH 7.8 CVE-2022-23453 Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of in… Support Assistant 9.11+ Fix from $1,9502023-02-01 HIGH 7.8 CVE-2022-23454 Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of in… Support Assistant 9.11+ Fix from $1,9502023-02-01 HIGH 7.8 CVE-2022-45099 Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially… Emc Powerscale Onefs 9.1.0.24 / 9.2.1.18+ Fix from $1,9502023-02-01 HIGH 8.8 CVE-2022-48199 SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges via a low-privileged user ac… Networx Mitigation only Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-47040 An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running the tcpdump command after pla… Rtf3505vw N1 Firmware No fix yet Fix from $1,9502023-01-26 MEDIUM 6.7 CVE-2022-3432 A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an at… Ideapad Y700 14isk Firmware Mitigation only Fix from $1,6002023-01-26 HIGH 7.8 CVE-2022-20456 In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead… Android Mitigation only Fix from $1,9502023-01-26 MEDIUM 6.7 CVE-2022-3430 A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify s… D330 10igl Firmware Mitigation only Fix from $1,6002023-01-23 HIGH 7.5 CVE-2022-1109 An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service. Leyun 6.8.21.99+ Fix from $1,9502023-01-20 MEDIUM 6.7 CVE-2023-20043 A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to … Cx Cloud Agent 1.9+ Fix from $1,6002023-01-20 HIGH 8.1 CVE-2022-45924 An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint itemtemplate.createtemplate2 allows a low-privilege user… Opentext Extended Ecm after 22.3 Fix from $1,9502023-01-18 HIGH 7.1 CVE-2020-36611 Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAI… Tuning Manager 8.8.5-00+ Fix from $1,9502023-01-17 CRITICAL 9.8 CVE-2023-23566 A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an acc… Axigen Mail Server Mitigation only Fix from $2,3002023-01-13 HIGH 7.5 CVE-2022-46761 The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malic… Emui 2.0+ Fix from $1,9502023-01-06 CRITICAL 9.8 CVE-2021-4297 A vulnerability has been found in trampgeek jobe up to 1.6.4 and classified as problematic. This vulnerability affects the function runs_post of the … Jobe 1.6.5+ Fix from $2,3002023-01-01