Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 8.1 CVE-2019-9579 An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended a… Illumos Patch available Fix from $1,9502022-12-26 HIGH 7.8 CVE-2022-3155 When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received fil… Thunderbird 102.3+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-29909 Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing pro… Firefox 91.9 / 100.0+ Fix from $1,9502022-12-22 MEDIUM 6.5 CVE-2022-47551 Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The root cause of the issue is the … Apiman after 2.2.3 Fix from $1,6002022-12-20 HIGH 7.8 CVE-2022-20611 In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. Th… Android Patch available Fix from $1,9502022-12-13 HIGH 7.8 CVE-2022-20474 In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead… Android Patch available Fix from $1,9502022-12-13 HIGH 7.8 CVE-2022-20475 In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This… Android Patch available Fix from $1,9502022-12-13 HIGH 7.8 CVE-2022-20495 In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in … Android Patch available Fix from $1,9502022-12-13 MEDIUM 6.5 CVE-2022-42446 Starting with Sametime 12, anonymous users are enabled by default. After logging in as an anonymous user, one has the ability to browse the User Dire… Sametime Mitigation only Fix from $1,6002022-12-12 HIGH 8.4 CVE-2022-37018 A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code executi… Z1 G3 Firmware 01.33 / 01.85+ Fix from $1,9502022-12-12 CRITICAL 9.8 CVE-2021-3437EPSS 16% Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of se… Omen Gaming Hub 1.0.44 / 11.6.3.0+ Fix from $2,3002022-12-12 HIGH 7.8 CVE-2022-1038 A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending th… Jumpstart Patch available Fix from $1,9502022-12-12 MEDIUM 5.5 CVE-2022-45118 OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the p… Openharmony after 3.1.4 Fix from $1,6002022-12-08 HIGH 8.8 CVE-2022-46382 RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 has Insecure Permissions. Afte… Digital Rebar after 4.10.8 Fix from $1,9502022-12-06 CRITICAL 9.8 CVE-2022-27773 A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated priv… Endpoint Manager 2021.1+ Fix from $2,3002022-12-05 CRITICAL 9.8 CVE-2022-44929 An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profil… Dvg G5402sp Firmware No fix yet Fix from $2,3002022-12-02 HIGH 8.8 CVE-2022-45562 Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account… Omnia Mpx Node Firmware after 1.4.9 Fix from $1,9502022-12-02 HIGH 7.8 CVE-2022-42718 Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially e… Labview Command Line Interface 22.3.1+ Fix from $1,9502022-12-01 HIGH 8.2 CVE-2022-4020 Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secur… Aspire A315 22g Firmware Mitigation only Fix from $1,9502022-11-28 HIGH 7.2 CVE-2022-41943 sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `custom… Sourcegraph 4.1.0+ Fix from $1,9502022-11-22 MEDIUM 5.3 CVE-2022-42127 The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permissions, … Digital Experience Platform 7.4.3.37+ Fix from $1,6002022-11-15 MEDIUM 5.3 CVE-2022-42128 The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows rem… Digital Experience Platform 7.4.3.5+ Fix from $1,6002022-11-15 HIGH 7.8 CVE-2022-36377 Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.… Nuc Kit Wireless Adapter Driver Installer 22.40.0+ Fix from $1,9502022-11-11 HIGH 7.5 CVE-2022-44554 The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module … Harmonyos No fix yet Fix from $1,9502022-11-09 HIGH 7.5 CVE-2022-44557 The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation o… Harmonyos No fix yet Fix from $1,9502022-11-09 HIGH 7.5 CVE-2022-44561 The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arb… Emui Mitigation only Fix from $1,9502022-11-09 CRITICAL 9.8 CVE-2022-34824 Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO … Expresscluster X after 5.0 Fix from $2,3002022-11-08 HIGH 7.8 CVE-2022-20441 In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to loc… Android Mitigation only Fix from $1,9502022-11-08 MEDIUM 5.5 CVE-2022-20448 In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could… Android Mitigation only Fix from $1,6002022-11-08 HIGH 7.8 CVE-2022-20452 In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to lo… Android Mitigation only Fix from $1,9502022-11-08