Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2021-39780 In Traceur, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could l… Android Mitigation only Fix from $1,9502022-03-30 MEDIUM 5.5 CVE-2021-39747 In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass. This could lead to local in… Android Mitigation only Fix from $1,6002022-03-30 MEDIUM 5.5 CVE-2021-39748 In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent. This could lead to local in… Android Mitigation only Fix from $1,6002022-03-30 HIGH 7.8 CVE-2021-1000 In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-1033 In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe PendingIntent. This could le… Android Mitigation only Fix from $1,9502022-03-30 MEDIUM 6.5 CVE-2022-22948 KEVEPSS 13% The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative ac… Cloud Foundation 3.11 / 4.4.1+ Fix from $1,6002022-03-29 HIGH 7.8 CVE-2022-26839 Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which… Diaenergie 1.8.02.004+ Fix from $1,9502022-03-29 HIGH 8.8 CVE-2021-40904 The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default),… Checkmk 1.6.0+ Fix from $1,9502022-03-25 HIGH 8.2 CVE-2021-44905 Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attacker to disable the lock via a… Fortessa Ftbtld Firmware No fix yet Fix from $1,9502022-03-25 CRITICAL 9.8 CVE-2022-27919 Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configura… Enterprise after 2021.4.3 Fix from $2,3002022-03-25 MEDIUM 5.3 CVE-2021-44751 A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in JavaScript or iFrame can tri… Safe 18.5+ Fix from $1,6002022-03-25 MEDIUM 6.5 CVE-2022-25570 In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permission… Passwordstate No fix yet Fix from $1,6002022-03-21 MEDIUM 5.5 CVE-2021-22571 A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded i… Sa360 Webquery To Bigquery Exporter 1.0.3+ Fix from $1,6002022-03-18 HIGH 8.1 CVE-2022-25364 In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed… Enterprise 2021.4.2+ Fix from $1,9502022-03-17 HIGH 7.8 CVE-2021-39694 In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass. T… Android Mitigation only Fix from $1,9502022-03-16 HIGH 7.8 CVE-2022-25815 PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action wi… Android Mitigation only Fix from $1,9502022-03-10 HIGH 7.8 CVE-2022-25814 PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized ac… Android Mitigation only Fix from $1,9502022-03-10 MEDIUM 5.5 CVE-2021-44216 Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access t… Cfengine 3.15.5 / 3.18.1+ Fix from $1,6002022-03-10 MEDIUM 5.5 CVE-2021-44215 Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact. Cfengine 3.15.5 / 3.18.1+ Fix from $1,6002022-03-10 MEDIUM 6.5 CVE-2021-40059 There is a permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect confidentiality. Emui No fix yet Fix from $1,6002022-03-10 CRITICAL 9.1 CVE-2021-40053 There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity. Emui No fix yet Fix from $2,3002022-03-10 HIGH 7.5 CVE-2021-40049 There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information… Emui No fix yet Fix from $1,9502022-03-10 MEDIUM 5.5 CVE-2021-20269 A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to read this file and leak kerne… Kexec Tools 2.0.20-47 / 2.0.21-8+ Fix from $1,6002022-03-10 HIGH 7.8 CVE-2022-25943 The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service progr… Wps Office 11.2.0.10258+ Fix from $1,9502022-03-09 MEDIUM 6.5 CVE-2021-38268 The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 21, 7.2 before fi… Digital Experience Platform 7.2.1 / 7.3.7+ Fix from $1,6002022-03-02 HIGH 7.5 CVE-2021-41652 Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database. Batflat Mitigation only Fix from $1,9502022-03-01 MEDIUM 5.5 CVE-2021-37103 There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confide… Emui No fix yet Fix from $1,6002022-02-25 MEDIUM 6.5 CVE-2022-24337 In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permissions. Teamcity 2021.2+ Fix from $1,6002022-02-25 MEDIUM 5.5 CVE-2022-25327 The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other u… Fscrypt 0.3.3+ Fix from $1,6002022-02-25 HIGH 7.8 CVE-2022-23104 WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the program Operator Wor… Win 911 2021 R1 Mitigation only Fix from $1,9502022-02-24