Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.5 CVE-2022-43574 "IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignment which could allow access … Robotic Process Automation 21.0.6+ Fix from $1,9502022-11-03 HIGH 7.8 CVE-2022-33182 A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authent… Fabric Operating System 8.2.3c / 9.0.1e+ Fix from $1,9502022-10-25 MEDIUM 5.5 CVE-2013-4281 In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users… Openshift Patch available Fix from $1,6002022-10-19 HIGH 7.8 CVE-2022-36438 AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used … Asusswitch 1.0.10.0 / 3.1.5.0+ Fix from $1,9502022-10-18 MEDIUM 6.0 CVE-2022-36439 AsusSoftwareManager.exe in ASUS System Control Interface on ASUS personal computers (running Windows) allows a local user to write into the Temp dire… Asusliveupdate 1.0.45.0 / 1.0.53.0+ Fix from $1,6002022-10-18 HIGH 8.8 CVE-2022-3368 A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to e… Avira Security after 1.1.71.30554 Fix from $1,9502022-10-17 HIGH 7.8 CVE-2022-42464 OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. T… Openharmony after 3.1.2 Fix from $1,9502022-10-14 HIGH 8.8 CVE-2022-36803 The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use… Jira Align 10.109.2+ Fix from $1,9502022-10-14 HIGH 8.0 CVE-2022-40187 Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all i… Gc3 Launch Monitor Firmware 1.5.0.2+ Fix from $1,9502022-10-13 HIGH 7.8 CVE-2022-33922 Dell GeoDrive, versions prior to 2.2, contains Insecure File and Folder Permissions vulnerabilities. A low privilege attacker could potentially explo… Geodrive 2.2.3+ Fix from $1,9502022-10-12 HIGH 7.8 CVE-2022-20435 There is a Unauthorized service in the system service, may cause the system reboot. Since the component does not have permission check and permission… Android Mitigation only Fix from $1,9502022-10-11 HIGH 7.8 CVE-2022-20436 There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege… Android Mitigation only Fix from $1,9502022-10-11 MEDIUM 6.7 CVE-2022-41748 A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with administrative c… Apex One Patch available Fix from $1,6002022-10-10 MEDIUM 5.3 CVE-2022-41414 An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site … Liferay Portal after 7.4.2 Fix from $1,6002022-10-07 HIGH 7.8 CVE-2022-26235 A vulnerability was discovered in the Remisol Advance v2.0.12.1 and below for the Normand Message Server. On installation, the permissions set by Rem… Remisol Advance after 2.0.12.1 Fix from $1,9502022-10-06 HIGH 7.8 CVE-2022-3263 The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileg… Scadapro Server Mitigation only Fix from $1,9502022-09-23 MEDIUM 5.5 CVE-2021-46834 A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. … Jad Al50 Firmware Mitigation only Fix from $1,6002022-09-20 HIGH 7.8 CVE-2022-38764 A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly permissiv… Housecall after 1.62.1.1133 Fix from $1,9502022-09-19 HIGH 7.8 CVE-2022-38466 A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default installation sets insecure file p… Coreshield One Way Gateway 2.2+ Fix from $1,9502022-09-13 MEDIUM 6.5 CVE-2022-2528 In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages. Octopus Server 2022.1.3106 / 2022.2.7718+ Fix from $1,6002022-09-09 MEDIUM 6.3 CVE-2022-31251 A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local attackers with control over th… Factory 22.05.2-3.3+ Fix from $1,6002022-09-07 HIGH 7.8 CVE-2022-2735 A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between… Debian Linux after 0.11.3 Fix from $1,9502022-09-06 CRITICAL 9.8 CVE-2022-40109 TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa. A3002r Firmware Mitigation only Fix from $2,3002022-09-06 CRITICAL 9.8 CVE-2022-36640 influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands… Influxdb 1.8.0+ Fix from $2,3002022-09-02 HIGH 7.5 CVE-2022-32743 Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it. Fedora 4.17.0+ Fix from $1,9502022-09-01 HIGH 7.8 CVE-2022-37173 An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe. Gvim Mitigation only Fix from $1,9502022-08-30 HIGH 8.8 CVE-2022-0336 The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the … Fedora 4.13.17 / 4.14.12+ Fix from $1,9502022-08-29 MEDIUM 5.5 CVE-2021-3917 A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw … Coreos Installer 0.10.0+ Fix from $1,6002022-08-23 MEDIUM 6.6 CVE-2021-3701 A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw all… Ansible Runner Patch available Fix from $1,6002022-08-23 HIGH 7.2 CVE-2021-37289 Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web… Mzk Dp150n Firmware No fix yet Fix from $1,9502022-08-22