Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
MEDIUM 6.7 CVE-2020-8701 Incorrect default permissions in installer for the Intel(R) SSD Toolbox versions before 2/9/2021 may allow a privileged user to potentially enable es… Solid State Drive Toolbox 2021-02-09+ Fix from $1,6002021-02-17 MEDIUM 5.5 CVE-2020-0524 Improper default permissions in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow an au… Ethernet Controller I210 Firmware 3.30+ Fix from $1,6002021-02-17 MEDIUM 5.3 CVE-2021-20653 Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and earlier, and CSDJ-A 03.08.00 and earlier) allows remote at… Csdj B Firmware after 03.08.00 Fix from $1,6002021-02-17 HIGH 7.8 CVE-2020-28392 A vulnerability has been identified in SIMARIS configuration (All versions < V4.0.1). During installation to default target folder, incorrect permiss… Simaris Configuration 4.0.1+ Fix from $1,9502021-02-09 MEDIUM 5.7 CVE-2020-16144 When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and ano… Files Antivirus 0.15.2+ Fix from $1,6002021-02-09 HIGH 7.8 CVE-2020-25245 A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writeable by normal users. As these… Digsi 4 4.94+ Fix from $1,9502021-02-09 HIGH 8.8 CVE-2021-3394EPSS 6% Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious… Millewin No fix yet Fix from $1,9502021-02-09 MEDIUM 5.3 CVE-2020-25208 In JetBrains YouTrack before 2020.4.4701, an attacker could enumerate users via the REST API without appropriate permissions. Youtrack 2020.4.4701+ Fix from $1,6002021-02-03 MEDIUM 5.3 CVE-2020-29582 In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such… Kotlin 2.1.0+ Fix from $1,6002021-02-03 CRITICAL 9.8 CVE-2019-20468 An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permissions such as READ_EXTERNAL_… Q90 Junior Gps Horloge Firmware Mitigation only Fix from $2,3002021-02-01 MEDIUM 5.5 CVE-2020-26941 A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file vi… Endpoint Antivirus after 13.2 Fix from $1,6002021-01-26 MEDIUM 6.5 CVE-2020-13922 Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API inter… Dolphinscheduler Mitigation only Fix from $1,6002021-01-11 HIGH 7.1 CVE-2021-1056 NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely hono… Debian Linux 390.141 / 450.102.04+ Fix from $1,9502021-01-08 CRITICAL 9.8 CVE-2020-13452 In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can… Gotenberg after 6.2.1 Fix from $2,3002021-01-07 MEDIUM 6.7 CVE-2020-29489 Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contains a plain-text password storage vulnerability. A user credentials (incl… Emc Unity Operating Environment 5.0.4.0.5.012+ Fix from $1,6002021-01-05 HIGH 7.8 CVE-2020-13539 An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via… Win 911 No fix yet Fix from $1,9502021-01-05 HIGH 7.8 CVE-2020-13540 An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via… Win 911 No fix yet Fix from $1,9502021-01-05 HIGH 8.8 CVE-2020-13541 An exploitable local privilege elevation vulnerability exists in the file system permissions of the Mobile-911 Server V2.5 install directory. Dependi… Mobile 911 Server No fix yet Fix from $1,9502021-01-05 HIGH 8.6 CVE-2020-29491 Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially … Wyse Thinos after 8.6 Fix from $1,9502021-01-04 CRITICAL 10.0 CVE-2020-29492 Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially … Wyse Thinos after 8.6 Fix from $2,3002021-01-04 HIGH 7.8 CVE-2020-13535 A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker can globally overwrite service … Linkmaster No fix yet Fix from $1,9502020-12-18 HIGH 7.8 CVE-2020-0486 In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local … Android Patch available Fix from $1,9502020-12-15 HIGH 7.8 CVE-2020-5798 inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user du… Insync No fix yet Fix from $1,9502020-12-07 HIGH 7.8 CVE-2020-13542 A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depending on the vector chosen, an … Logicaldoc No fix yet Fix from $1,9502020-12-03 HIGH 7.8 CVE-2020-8539 Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized c… Head Unit Firmware No fix yet Fix from $1,9502020-12-01 HIGH 7.3 CVE-2020-12510 The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and furthe… Twincat Extended Automation Runtime Mitigation only Fix from $1,9502020-11-19 MEDIUM 6.5 CVE-2020-13351 Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pip… GitLab 13.3.9 / 13.4.5+ Fix from $1,6002020-11-17 HIGH 7.8 CVE-2020-12346 Improper permissions in the installer for the Intel(R) Battery Life Diagnostic Tool before version 1.0.7 may allow an authenticated user to potential… Battery Life Diagnostic Tool 1.0.7+ Fix from $1,9502020-11-12 HIGH 7.8 CVE-2020-24456 Incorrect default permissions in the Intel(R) Board ID Tool version v.1.01 may allow an authenticated user to potentially enable escalation of privil… Board Id Tool Mitigation only Fix from $1,9502020-11-12 MEDIUM 5.5 CVE-2020-24460 Incorrect default permissions in the Intel(R) DSA before version 20.8.30.6 may allow an authenticated user to potentially enable denial of service vi… Driver \& Support Assistant 20.8.30.6+ Fix from $1,6002020-11-12