Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
MEDIUM 5.5 CVE-2022-27500 Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated user to potentially enable info… Support 21.7.40+ Fix from $1,6002022-08-18 CRITICAL 9.8 CVE-2022-25899 Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated use… Open Active Management Technology Cloud Toolkit 2.0.2 / 2.2.2+ Fix from $2,3002022-08-18 HIGH 7.8 CVE-2022-26344 Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable esca… Single Event Api Mitigation only Fix from $1,9502022-08-18 MEDIUM 5.5 CVE-2021-44470 Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authenticated user to potentially enab… Connect M 1.7.4+ Fix from $1,6002022-08-18 MEDIUM 6.5 CVE-2021-39087 IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow an authenticat… Sterling B2b Integrator 6.0.3.6 / 6.1.0.5+ Fix from $1,6002022-08-16 HIGH 7.8 CVE-2021-30490 upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticate… Viewpower after 1.04-21353 Fix from $1,9502022-08-16 MEDIUM 5.5 CVE-2022-20272 In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could l… Android Mitigation only Fix from $1,6002022-08-12 HIGH 7.8 CVE-2022-20246 In WindowManager, there is a possible bypass of the restrictions for starting activities from the background due to an incorrect UID/permission check… Android Mitigation only Fix from $1,9502022-08-11 CRITICAL 9.8 CVE-2022-37003 The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauth… Emui No fix yet Fix from $2,3002022-08-10 HIGH 7.5 CVE-2022-37006 Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability. Emui No fix yet Fix from $1,9502022-08-10 HIGH 7.8 CVE-2022-37030 Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a local unprivileged user in the g… Gromox 1.28+ Fix from $1,9502022-08-04 MEDIUM 5.5 CVE-2022-22424 IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. I… Qradar Security Information And Event Manager 7.3.3 / 7.4.3+ Fix from $1,6002022-07-20 CRITICAL 9.1 CVE-2022-34737 The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity… Emui No fix yet Fix from $2,3002022-07-12 MEDIUM 5.5 CVE-2022-30758 Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with pr… Android Mitigation only Fix from $1,6002022-07-12 MEDIUM 5.3 CVE-2022-2366 Incorrect default configuration for trusted IP header in Mattermost version 6.7.0 and earlier allows attacker to bypass some of the rate limitations … Mattermost Server 6.3.9 / 6.5.2+ Fix from $1,6002022-07-12 CRITICAL 9.8 CVE-2022-32207EPSS 7% When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from … Curl 7.84.0+ Fix from $2,3002022-07-07 HIGH 8.8 CVE-2022-33996 Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that … Devolutions Server 2022.2.0+ Fix from $1,9502022-07-07 MEDIUM 5.3 CVE-2022-2270 An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all v… GitLab 14.10.5 / 15.0.4+ Fix from $1,6002022-07-01 HIGH 7.5 CVE-2022-33023 CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong. Cva6 Mitigation only Fix from $1,9502022-06-29 HIGH 8.8 CVE-2021-41635 When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnera… Ftp Server No fix yet Fix from $1,9502022-06-24 HIGH 7.1 CVE-2021-41637 Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among… Ftp Server No fix yet Fix from $1,9502022-06-24 HIGH 8.8 CVE-2022-1833 A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where th… Amq Broker Mitigation only Fix from $1,9502022-06-21 HIGH 7.8 CVE-2022-33912 A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise ed… Checkmk Mitigation only Fix from $1,9502022-06-17 HIGH 8.8 CVE-2022-32562 An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission. Couchbase Server after 7.0.4 Fix from $1,9502022-06-13 MEDIUM 5.3 CVE-2021-46811 HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Productio… Emui Mitigation only Fix from $1,6002022-06-13 MEDIUM 5.5 CVE-2022-25804 An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig registry key (under JavaSoft… Universal Management Suite No fix yet Fix from $1,6002022-06-09 MEDIUM 5.5 CVE-2022-30747 PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without permission via implicit Inten… Smartthings 1.7.85.25+ Fix from $1,6002022-06-07 HIGH 7.8 CVE-2022-31500 In KNIME Analytics Platform below 4.6.0, the Windows installer sets improper filesystem permissions. Knime Analytics Platform 4.6.0+ Fix from $1,9502022-06-02 HIGH 7.8 CVE-2022-29483 Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating… E Design after 1.12.2.0004 Fix from $1,9502022-06-02 MEDIUM 5.5 CVE-2022-28702 Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating… E Design after 1.12.2.0004 Fix from $1,6002022-06-02