Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2020-8933 A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/co… Guest Oslogin after 20200507.00 Fix from $1,9502020-06-22 HIGH 7.8 CVE-2020-3626 Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Snapdragon Compute, Snapdragon C… Apq8053 Firmware Mitigation only Fix from $1,9502020-06-22 CRITICAL 9.8 CVE-2017-18915 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoin… Mattermost Server 3.6.7 / 3.7.5+ Fix from $2,3002020-06-19 MEDIUM 5.3 CVE-2019-20889 An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation. Mattermost Server 4.10.5 / 5.5.2+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2019-20882 An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team. Mattermost Server 5.8.0+ Fix from $1,6002020-06-19 HIGH 7.8 CVE-2020-14019 Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, an… Rtslib Fb after 2.1.72 Fix from $1,9502020-06-19 MEDIUM 6.5 CVE-2020-10782 An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable … Ansible Tower Mitigation only Fix from $1,6002020-06-18 HIGH 7.5 CVE-2019-9943 In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model o… Omero.server after 5.6.0 Fix from $1,9502020-06-17 HIGH 8.8 CVE-2020-14156 user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions. Openbmc 2020-04-03+ Fix from $1,9502020-06-15 HIGH 7.8 CVE-2020-0215 In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypass. This could lead to local e… Android Mitigation only Fix from $1,9502020-06-11 HIGH 7.8 CVE-2020-0208 In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additi… Android Patch available Fix from $1,9502020-06-11 HIGH 7.8 CVE-2020-0209 In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additi… Android Patch available Fix from $1,9502020-06-11 HIGH 7.3 CVE-2020-0133 In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to lo… Android Patch available Fix from $1,9502020-06-11 HIGH 7.8 CVE-2020-9817 A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Catalina 10.15.5. A malicious… Mac Os X 10.13.6 / 10.14.6+ Fix from $1,9502020-06-09 HIGH 7.8 CVE-2020-13884 Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges d… Workspace App 2006.1+ Fix from $1,9502020-06-08 HIGH 7.8 CVE-2020-13885 Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the app… Workspace App 2006.1+ Fix from $1,9502020-06-08 MEDIUM 5.4 CVE-2020-8954 OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated] Openbrowser Mitigation only Fix from $1,6002020-06-08 HIGH 7.5 CVE-2020-12695EPSS 15% The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on… Wap131 2.0.0+ Fix from $1,9502020-06-08 HIGH 7.5 CVE-2020-13894 handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field. Dext5 after 3.5.1402961 Fix from $1,9502020-06-07 MEDIUM 5.5 CVE-2020-13867 Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files). Fedora after 2.1.52 Fix from $1,6002020-06-05 MEDIUM 6.5 CVE-2020-6497 Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a c… Chrome 83.0.4103.88+ Fix from $1,6002020-06-03 MEDIUM 6.5 CVE-2020-6498 Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a c… Chrome 83.0.4103.88+ Fix from $1,6002020-06-03 MEDIUM 6.5 CVE-2020-6501 Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a craft… Chrome 80.0.3987.87+ Fix from $1,6002020-06-03 MEDIUM 6.5 CVE-2020-6502 Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page. Chrome 80.0.3987.87+ Fix from $1,6002020-06-03 MEDIUM 6.5 CVE-2020-6495 Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malic… Chrome 83.0.4103.97+ Fix from $1,6002020-06-03 HIGH 7.7 CVE-2017-18868 Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack upon whi… Xbee 2 Firmware Mitigation only Fix from $1,9502020-05-21 MEDIUM 6.5 CVE-2020-6487 Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a… Chrome 83.0.4103.61+ Fix from $1,6002020-05-21 MEDIUM 6.5 CVE-2020-6480 Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation restrictions via U… Chrome 83.0.4103.61+ Fix from $1,6002020-05-21 MEDIUM 6.5 CVE-2020-6482 Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic… Chrome 83.0.4103.61+ Fix from $1,6002020-05-21 MEDIUM 6.5 CVE-2020-6483 Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a … Chrome 83.0.4103.61+ Fix from $1,6002020-05-21