Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 8.8 CVE-2022-29376 Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary … Xampp after 8.1.4 Fix from $1,9502022-05-23 HIGH 8.8 CVE-2022-28999 Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binar… Dev C\+\+ No fix yet Fix from $1,9502022-05-23 CRITICAL 9.8 CVE-2022-28932 D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions. Dsl G2452dg Firmware Mitigation only Fix from $2,3002022-05-23 HIGH 8.2 CVE-2022-29178 Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Cilium prior to versi… Cilium 1.9.16 / 1.10.11+ Fix from $1,9502022-05-20 HIGH 7.8 CVE-2022-29162 runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 wh… Fedora 1.1.2+ Fix from $1,9502022-05-17 HIGH 7.8 CVE-2022-0486 Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with loc… Deception 9.4.5+ Fix from $1,9502022-05-17 HIGH 7.8 CVE-2022-0997 Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, admin… Deception 9.4.5+ Fix from $1,9502022-05-17 MEDIUM 6.5 CVE-2022-30367 Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img. Air Cargo Management System No fix yet Fix from $1,6002022-05-13 MEDIUM 6.5 CVE-2022-30375 Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img. Simple Social Networking Site No fix yet Fix from $1,6002022-05-13 HIGH 7.5 CVE-2022-23802 Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to p… Guru Mitigation only Fix from $1,9502022-05-06 HIGH 7.5 CVE-2022-29585 In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are … Mahara 20.10.5 / 21.04.4+ Fix from $1,9502022-04-28 MEDIUM 5.5 CVE-2022-28218 An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (found in a Roundcube configur… Webmail Messenger 4.2.1+ Fix from $1,6002022-04-26 MEDIUM 5.0 CVE-2021-3722 A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configuration files to be written to… Pcmanager 4.0.40.2175+ Fix from $1,6002022-04-22 HIGH 7.8 CVE-2022-20732 A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an authenticated, local attacker … Virtualized Infrastructure Manager 4.2.2+ Fix from $1,9502022-04-21 HIGH 7.5 CVE-2022-29547 The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This c… Createredirect 2022-04-14+ Fix from $1,9502022-04-21 HIGH 7.0 CVE-2021-43986 The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replac… Roboguide after 9.40083.00.05 Fix from $1,9502022-04-20 MEDIUM 5.3 CVE-2022-27652 A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker En… Cri O 20.10.14+ Fix from $1,6002022-04-18 MEDIUM 6.5 CVE-2011-1762 A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow… WordPress 3.0.6 / 3.1.2+ Fix from $1,6002022-04-18 HIGH 7.8 CVE-2021-39794 In broadcastPortInfo of AdbService.java, there is a possible way for apps to run code as the shell user, if wireless debugging is enabled, due to a m… Android Mitigation only Fix from $1,9502022-04-12 MEDIUM 5.3 CVE-2022-24804 Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior 2.9.0.beta4 erroneously expo… Discourse 2.8.3+ Fix from $1,6002022-04-11 MEDIUM 5.4 CVE-2022-27958 Insecure permissions configured in the userid parameter at /user/getuserprofile of FEBS-Security v1.0 allows attackers to access and arbitrarily modi… Febs Security No fix yet Fix from $1,6002022-04-10 MEDIUM 5.4 CVE-2022-27960 Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify … Ofcms No fix yet Fix from $1,6002022-04-10 MEDIUM 5.5 CVE-2022-26855 Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local malicious user could potentially expl… Emc Powerscale Onefs after 9.3.0.0 Fix from $1,6002022-04-08 MEDIUM 6.5 CVE-2022-22518 A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymous access to components part o… Control For Beaglebone Sl 4.5.0.0+ Fix from $1,6002022-04-07 HIGH 7.5 CVE-2022-27649 A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker E… Developer Tools Patch available Fix from $1,9502022-04-04 HIGH 7.5 CVE-2022-27650 A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engi… Fedora 1.4.4+ Fix from $1,9502022-04-04 MEDIUM 6.8 CVE-2022-27651 A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) whe… Fedora 1.25.0+ Fix from $1,6002022-04-04 MEDIUM 5.5 CVE-2021-39769 In Device Policy, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. Thi… Android Mitigation only Fix from $1,6002022-03-30 MEDIUM 5.5 CVE-2021-39770 In Framework, there is a possible disclosure of the device owner package due to a missing permission check. This could lead to local information disc… Android Mitigation only Fix from $1,6002022-03-30 MEDIUM 5.5 CVE-2021-39779 In getCallStateUsingPackage of Telecom Service, there is a missing permission check. This could lead to local information disclosure of the call stat… Android Mitigation only Fix from $1,6002022-03-30