Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2022-43574
"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access …
Robotic Process Automation
21.0.6+
HIGH 7.8
CVE-2022-33182
A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authent…
Fabric Operating System
8.2.3c / 9.0.1e+
MEDIUM 5.5
CVE-2013-4281
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users…
Openshift
Patch available
HIGH 7.8
CVE-2022-36438
AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used …
Asusswitch
1.0.10.0 / 3.1.5.0+
MEDIUM 6.0
CVE-2022-36439
AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp dire…
Asusliveupdate
1.0.45.0 / 1.0.53.0+
HIGH 8.8
CVE-2022-3368
A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to e…
Avira Security
after 1.1.71.30554
HIGH 7.8
CVE-2022-42464
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. T…
Openharmony
after 3.1.2
HIGH 8.8
CVE-2022-36803
The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use…
Jira Align
10.109.2+
HIGH 8.0
CVE-2022-40187
Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all i…
Gc3 Launch Monitor Firmware
1.5.0.2+
HIGH 7.8
CVE-2022-33922
Dell GeoDrive, versions prior to 2.2, contains Insecure File and Folder Permissions vulnerabilities. A low privilege attacker could potentially explo…
Geodrive
2.2.3+
HIGH 7.8
CVE-2022-20435
There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission…
Android
Mitigation only
HIGH 7.8
CVE-2022-20436
There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege…
Android
Mitigation only
MEDIUM 6.7
CVE-2022-41748
A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with administrative c…
Apex One
Patch available
MEDIUM 5.3
CVE-2022-41414
An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site …
Liferay Portal
after 7.4.2
HIGH 7.8
CVE-2022-26235
A vulnerability was discovered in the Remisol Advance v2.0.12.1 and below for the Normand Message Server. On installation, the permissions set by Rem…
Remisol Advance
after 2.0.12.1
HIGH 7.8
CVE-2022-3263
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileg…
Scadapro Server
Mitigation only
MEDIUM 5.5
CVE-2021-46834
A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. …
Jad Al50 Firmware
Mitigation only
HIGH 7.8
CVE-2022-38764
A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissiv…
Housecall
after 1.62.1.1133
HIGH 7.8
CVE-2022-38466
A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file p…
Coreshield One Way Gateway
2.2+
MEDIUM 6.5
CVE-2022-2528
In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages.
Octopus Server
2022.1.3106 / 2022.2.7718+
MEDIUM 6.3
CVE-2022-31251
A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over th…
Factory
22.05.2-3.3+
HIGH 7.8
CVE-2022-2735
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between…
Debian Linux
after 0.11.3
CRITICAL 9.8
CVE-2022-40109
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.
A3002r Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-36640
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands…
Influxdb
1.8.0+
HIGH 7.5
CVE-2022-32743
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.
Fedora
4.17.0+
HIGH 7.8
CVE-2022-37173
An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.
Gvim
Mitigation only
HIGH 8.8
CVE-2022-0336
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the …
Fedora
4.13.17 / 4.14.12+
MEDIUM 5.5
CVE-2021-3917
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw …
Coreos Installer
0.10.0+
MEDIUM 6.6
CVE-2021-3701
A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw all…
Ansible Runner
Patch available
HIGH 7.2
CVE-2021-37289
Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web…
Mzk Dp150n Firmware
No fix yet