Vulnerability index

Browse CVEs

1,384 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2020-12354 Incorrect default permissions in Windows(R) installer in Intel(R) AMT SDK versions before 14.0.0.1 may allow an authenticated user to potentially ena… Active Management Technology Software Development Kit 14.0.0.1+ Fix from $1,9502020-11-12 HIGH 7.8 CVE-2020-13770 Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as thes… Endpoint Manager after 2020.1.1 Fix from $1,9502020-11-12 HIGH 7.8 CVE-2020-12306 Incorrect default permissions in the Intel(R) RealSense(TM) D400 Series Dynamic Calibration Tool before version 2.11, may allow an authenticated user… Realsense D400 Series Dynamic Calibration Tool 2.11+ Fix from $1,9502020-11-12 HIGH 7.8 CVE-2020-12307 Improper permissions in some Intel(R) High Definition Audio drivers before version 9.21.00.4561 may allow an authenticated user to potentially enable… High Definition Audio Driver 9.21.00.4561+ Fix from $1,9502020-11-12 MEDIUM 5.3 CVE-2020-26809 SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpo… Commerce Cloud No fix yet Fix from $1,6002020-11-10 HIGH 7.8 CVE-2020-13536 An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on t… Mxview No fix yet Fix from $1,9502020-11-05 HIGH 7.8 CVE-2020-13537 An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on t… Mxview No fix yet Fix from $1,9502020-11-05 MEDIUM 6.5 CVE-2020-28041 The SIP ALG implementation on NETGEAR Nighthawk R7000 1.0.9.64_10.2.64 devices allows remote attackers to communicate with arbitrary TCP and UDP serv… Nighthawk R7000 Firmware No fix yet Fix from $1,6002020-11-02 MEDIUM 6.8 CVE-2020-28044 An attacker with physical access to a PAX Point Of Sale device with ProlinOS through 2.4.161.8859R can boot it in management mode, enable the XCB ser… Prolinos after 2.4.161.8859r Fix from $1,6002020-11-02 MEDIUM 6.7 CVE-2019-14718 Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection … Mx900 Firmware Mitigation only Fix from $1,6002020-10-23 HIGH 7.5 CVE-2020-27665 In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes. Strapi 3.2.5+ Fix from $1,9502020-10-22 HIGH 7.3 CVE-2020-17381 An issue was discovered in Ghisler Total Commander 9.51. Due to insufficient access restrictions in the default installation directory, an attacker c… Total Commander No fix yet Fix from $1,9502020-10-21 HIGH 7.3 CVE-2020-15843 ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folder permissions on %PROGRAMFILE… Actfax No fix yet Fix from $1,9502020-09-24 HIGH 7.8 CVE-2020-15850 Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interf… Backup \& Replication Director No fix yet Fix from $1,9502020-09-24 MEDIUM 5.5 CVE-2020-26088 A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create r… Linux Kernel 5.8.2+ Fix from $1,6002020-09-24 MEDIUM 5.5 CVE-2020-0294 In bindWallpaperComponentLocked of WallpaperManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lea… Android Mitigation only Fix from $1,6002020-09-18 HIGH 7.8 CVE-2020-0374 In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution pr… Android Mitigation only Fix from $1,9502020-09-17 HIGH 7.8 CVE-2020-0275 In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypa… Android Mitigation only Fix from $1,9502020-09-17 HIGH 7.8 CVE-2020-0388 In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permissions bypass due to an empty mutable PendingInten… Android Patch available Fix from $1,9502020-09-17 MEDIUM 5.5 CVE-2020-0390 In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution pri… Android Patch available Fix from $1,6002020-09-17 MEDIUM 5.5 CVE-2020-8346 A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 th… System Interface Foundation 1.1.19.5+ Fix from $1,6002020-09-15 HIGH 7.3 CVE-2020-10049 A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The start-stop scripts for the services of the affecte… Simatic Rtls Locating Manager 2.10.2+ Fix from $1,9502020-09-09 HIGH 7.8 CVE-2020-10050 A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The directory of service executables of the affected a… Simatic Rtls Locating Manager 2.10.2+ Fix from $1,9502020-09-09 HIGH 7.8 CVE-2019-10679 Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFILES(X86)%\Thomson Reuters\Eiko… Eikon No fix yet Fix from $1,9502020-09-03 HIGH 7.5 CVE-2020-23971 gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to… Gmapfp No fix yet Fix from $1,9502020-09-01 HIGH 7.5 CVE-2020-24583 An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMIS… Django 2.2.16 / 3.0.10+ Fix from $1,9502020-09-01 HIGH 7.5 CVE-2020-24584 An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level direc… Django 2.2.16 / 3.0.10+ Fix from $1,9502020-09-01 HIGH 7.8 CVE-2020-7527 Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access contr… Somove after 2.8.1 Fix from $1,9502020-08-31 MEDIUM 6.8 CVE-2020-13468 Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (w… Gd32f130 Firmware No fix yet Fix from $1,6002020-08-31 HIGH 7.8 CVE-2020-24717 OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to… Openzfs after 0.8.4 Fix from $1,9502020-08-27