Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.1
CVE-2021-31217
In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.
Dameware Mini Remote Control
Mitigation only
MEDIUM 5.3
CVE-2021-32725
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were n…
Nextcloud Server
19.0.13 / 20.0.11+
MEDIUM 6.1
CVE-2021-33214
In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information …
Ecatcher
after 6.6.4
HIGH 7.1
CVE-2021-26274
The Agent in NinjaRMM 5.0.909 has Insecure Permissions.
Ninjarmm
No fix yet
MEDIUM 5.3
CVE-2021-22346
There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may lead to the disclosu…
Emui
Mitigation only
HIGH 7.5
CVE-2021-22368
There is a Permission Control Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect normal use of the device.
Emui
No fix yet
HIGH 7.5
CVE-2021-22371
There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confi…
Emui
No fix yet
MEDIUM 5.5
CVE-2021-20490
IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X…
Spectrum Protect Plus
after 10.1.8
HIGH 7.5
CVE-2021-21737
A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attack…
Zxv10 B860h V5.0 Firmware
Mitigation only
MEDIUM 6.7
CVE-2021-34387
The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserve…
Jetson Linux
32.5.1+
HIGH 7.8
CVE-2021-0143
Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentia…
Brand Verification Tool
11.0.0.1225+
HIGH 7.2
CVE-2021-21736
A smart camera product of ZTE is impacted by a permission and access control vulnerability. Due to the defect of user permission management by the cl…
Zxhn Hs562 Firmware
Mitigation only
HIGH 7.8
CVE-2021-31998
A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE…
Inn
2.6.2+
HIGH 7.8
CVE-2021-0058
Incorrect default permissions in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to p…
Lapbc510 Firmware
1.1+
HIGH 7.8
CVE-2021-0100
Incorrect default permissions in the installer for the Intel(R) SSD Data Center Tool, versions downloaded before 12/31/2020, may allow an authenticat…
Ssd Data Center Tool
2020-12-31+
HIGH 7.8
CVE-2021-0106
Incorrect default permissions in the Intel(R) Optane(TM) DC Persistent Memory for Windows software versions before 2.00.00.3842 or 1.00.00.3515 may a…
Ipmctl
1.00.00.3515 / 2.00.00.3842+
HIGH 7.8
CVE-2020-27384
The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated U…
Guild Wars 2
No fix yet
HIGH 7.8
CVE-2021-27032
Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited privileges could run any number…
Licensing Services
Mitigation only
HIGH 7.8
CVE-2020-10145
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By …
Coldfusion
Mitigation only
HIGH 7.5
CVE-2021-33506
jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This can allow an attacker to circu…
Jitsi Meet
2.0.5963+
HIGH 7.5
CVE-2021-33038
An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a private mailing list's archives, th…
Debian Linux
after 1.3.4
HIGH 7.8
CVE-2020-9450
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe exposes a REST API that can be used by everyone, even unpr…
True Image 2020
No fix yet
MEDIUM 5.5
CVE-2020-9451
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where unprivileged users have writ…
True Image 2020
No fix yet
HIGH 8.8
CVE-2020-28906
Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged…
Fusion
after 5.7.5
MEDIUM 5.3
CVE-2020-13667
Access bypass vulnerability in of Drupal Core Workspaces allows an attacker to access data without correct permissions. The Workspaces module doesn't…
Drupal
8.8.10 / 8.9.6+
HIGH 7.5
CVE-2020-21342
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
Zzcms
No fix yet
HIGH 7.3
CVE-2021-28649
An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an …
Housecall For Home Networks
after 5.3.1179
HIGH 7.3
CVE-2021-31519
An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could a…
Housecall For Home Networks
after 5.3.1179
HIGH 7.8
CVE-2021-25319
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to es…
Factory
after 6.1.20-1.1
MEDIUM 6.5
CVE-2021-26804
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extens…
Centreon Web
Mitigation only