Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
MEDIUM 6.5 CVE-2019-10472 A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to an attacker-specified SSH ser… Libvirt Slaves after 1.8.5 Fix from $1,6002019-10-23 MEDIUM 6.5 CVE-2019-10463 A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker… Dynatrace Application Monitoring after 2.1.4 Fix from $1,6002019-10-23 HIGH 7.5 CVE-2019-16919 Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account… Cloud Foundation 1.8.4+ Fix from $1,9502019-10-18 HIGH 7.8 CVE-2019-14737 Ubisoft Uplay 92.0.0.6280 has Insecure Permissions. Uplay No fix yet Fix from $1,9502019-10-14 HIGH 7.8 CVE-2019-17043 An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevat… Patrol Agent Mitigation only Fix from $1,9502019-10-14 HIGH 7.8 CVE-2019-17044 An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" … Patrol Agent Patch available Fix from $1,9502019-10-14 HIGH 7.8 CVE-2019-2114 In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permissi… Android Patch available Fix from $1,9502019-10-11 HIGH 7.8 CVE-2019-2173 In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check. This could lead … Android Patch available Fix from $1,9502019-10-11 MEDIUM 6.7 CVE-2019-14510 An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdm… Vsa after 9.5.0.22 Fix from $1,6002019-10-11 HIGH 8.8 CVE-2015-9474 The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates. Simpolio No fix yet Fix from $1,9502019-10-10 HIGH 8.8 CVE-2015-9475 The Pont theme 1.5 for WordPress has insufficient restrictions on option updates. Pont No fix yet Fix from $1,9502019-10-10 HIGH 8.8 CVE-2015-9476 The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates. Teardrop Mitigation only Fix from $1,9502019-10-10 HIGH 8.8 CVE-2015-9477 The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates. Vernissage Mitigation only Fix from $1,9502019-10-10 HIGH 7.8 CVE-2019-17365 Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is worl… Nix after 2.3 Fix from $1,9502019-10-09 CRITICAL 9.8 CVE-2019-17124EPSS 23% Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. Viaware No fix yet Fix from $2,3002019-10-09 CRITICAL 9.8 CVE-2019-17383 The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesy… Netaddr 1.5.3 / 2.0.4+ Fix from $2,3002019-10-09 HIGH 7.8 CVE-2019-16913 PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user full permissi… Antivirus No fix yet Fix from $1,9502019-10-07 HIGH 7.1 CVE-2019-3688 The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterpris… Suse Linux Enterprise Server Mitigation only Fix from $1,9502019-10-07 HIGH 7.8 CVE-2018-19592 The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take cont… Link Mitigation only Fix from $1,9502019-09-27 MEDIUM 6.7 CVE-2019-12670 A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the name… iOS Mitigation only Fix from $1,6002019-09-25 CRITICAL 9.8 CVE-2019-3689 The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and… Nfs Utils after 2.1.1-6.10.2 Fix from $2,3002019-09-19 HIGH 8.8 CVE-2019-9679 Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected product… Ipc Hdw1x2x Firmware 2019-08-18+ Fix from $1,9502019-09-18 MEDIUM 5.5 CVE-2019-16355 The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files. Beego No fix yet Fix from $1,6002019-09-16 HIGH 7.5 CVE-2019-16106 The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the r… Humatrix Mitigation only Fix from $1,9502019-09-10 HIGH 7.2 CVE-2019-16186 In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions. Limesurvey 3.17.14+ Fix from $1,9502019-09-09 HIGH 7.2 CVE-2019-16185 In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions. Limesurvey 3.17.14+ Fix from $1,9502019-09-09 MEDIUM 5.5 CVE-2019-15716 WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the per… Wtf 0.19.0+ Fix from $1,6002019-08-28 HIGH 7.1 CVE-2019-5687 NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which … Gpu Driver Mitigation only Fix from $1,9502019-08-06 HIGH 7.5 CVE-2019-9630 Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and im… Nexus Repository Manager 3.17.0+ Fix from $1,9502019-07-08 HIGH 7.0 CVE-2019-7588 A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege escalation can potentially be a… Enterprise System Manager after 5.12.2 Fix from $1,9502019-06-18