Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2022-23922 WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write files to the Program Announcer di… Win 911 2021 R1 Mitigation only Fix from $1,9502022-02-24 HIGH 7.1 CVE-2021-45083 An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that… Fedora 3.3.1+ Fix from $1,9502022-02-20 MEDIUM 6.3 CVE-2021-3948 An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be ab… Migration Toolkit 1.5.2 / 1.6.3+ Fix from $1,6002022-02-18 MEDIUM 5.5 CVE-2021-3155 snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local atta… Snapd 2.54.3+ Fix from $1,6002022-02-17 CRITICAL 9.8 CVE-2021-20001 It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions… Debian Linux 2.12.16+ Fix from $2,3002022-02-11 CRITICAL 9.1 CVE-2021-39635 ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No ph… Android Mitigation only Fix from $2,3002022-02-11 CRITICAL 9.8 CVE-2021-39658 ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions o… Android Mitigation only Fix from $2,3002022-02-11 CRITICAL 9.8 CVE-2020-14521 Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker cou… C Controller Interface Module Utility after 3.42u Fix from $2,3002022-02-11 HIGH 7.8 CVE-2022-21204 Improper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation o… Quartus Prime 21.3+ Fix from $1,9502022-02-09 HIGH 7.8 CVE-2021-33129 Incorrect default permissions in the software installer for the Intel(R) Advisor before version 2021.4.0 may allow an authenticated user to potential… Advisor 2021.4.0+ Fix from $1,9502022-02-09 MEDIUM 5.5 CVE-2021-33166 Incorrect default permissions for the Intel(R) RXT for Chromebook application, all versions, may allow an authenticated user to potentially enable in… Retail Experience Tool Mitigation only Fix from $1,6002022-02-09 HIGH 7.8 CVE-2021-22817 A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to loca… Hmibmuhi29d2801 Firmware Mitigation only Fix from $1,9502022-02-09 HIGH 7.8 CVE-2022-24113 Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (W… Agent Mitigation only Fix from $1,9502022-02-04 MEDIUM 6.5 CVE-2022-24301 In Minetest before 5.4.0, players can add or subtract items from a different player's inventory. Debian Linux 5.4.0+ Fix from $1,6002022-02-02 CRITICAL 9.8 CVE-2021-46093 eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php. Elite Cms No fix yet Fix from $2,3002022-02-01 HIGH 8.8 CVE-2021-40416 An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. Al… Rlc 410w Firmware No fix yet Fix from $1,9502022-01-28 HIGH 8.8 CVE-2021-40388 A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system to escalate … Sq Manager No fix yet Fix from $1,9502022-01-28 HIGH 8.8 CVE-2021-40389 A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in… Deviceon\/iedge No fix yet Fix from $1,9502022-01-28 HIGH 8.8 CVE-2021-40396 A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the… Deviceon\/iservice No fix yet Fix from $1,9502022-01-28 HIGH 7.8 CVE-2021-40397 A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-crafted file can be replaced in … Wise Paas\/ota No fix yet Fix from $1,9502022-01-28 HIGH 7.1 CVE-2021-40413 An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. Th… Rlc 410w Firmware No fix yet Fix from $1,9502022-01-28 HIGH 7.1 CVE-2021-40414 An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. Th… Rlc 410w Firmware No fix yet Fix from $1,9502022-01-28 MEDIUM 6.5 CVE-2021-40415 An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. In… Rlc 410w Firmware No fix yet Fix from $1,6002022-01-28 MEDIUM 5.3 CVE-2021-41166 The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to … Nextcloud 3.17.1+ Fix from $1,6002022-01-26 MEDIUM 6.5 CVE-2021-46085 OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond their authority. Oneblog after 2.2.8 Fix from $1,6002022-01-25 HIGH 7.5 CVE-2021-46086 xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsa… Xzs Mysql No fix yet Fix from $1,9502022-01-25 MEDIUM 5.3 CVE-2022-22296 Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id parameter in manage_user endpoint. S… Hospital\'s Patient Records Management System Mitigation only Fix from $1,6002022-01-24 MEDIUM 5.5 CVE-2022-21704 log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile ap… Debian Linux 6.4.0+ Fix from $1,6002022-01-19 HIGH 8.6 CVE-2021-43860 Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the… Fedora 1.10.6+ Fix from $1,9502022-01-12 CRITICAL 9.8 CVE-2021-45003 Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php throu… Laundry Booking Management System No fix yet Fix from $2,3002022-01-10