Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Qiata HIGH 7.8
CVE-2023-40361

SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privile…

No fix yet
Fix from $1,950 2023-10-20
Bentley Nevada 3500 System Firmware HIGH 7.5
CVE-2023-34437

Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could a…

Mitigation only
Fix from $1,950 2023-10-19
Junos MEDIUM 5.5
CVE-2023-44201

An Incorrect Permission Assignment for Critical Resource vulnerability in a specific file of Juniper Networks Junos OS and Junos OS Evolved allows a …

Fix: 20.4+
Fix from $1,600 2023-10-13
Zabbix CRITICAL 9.1
CVE-2023-32723

Request to LDAP is sent before user permissions are checked.

Fix: 4.0.19 / 4.4.7+
Fix from $2,300 2023-10-12
Zabbix HIGH 8.8
CVE-2023-32724

Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.

Fix: after 6.4.5
Fix from $1,950 2023-10-12
Sicam Pas\/pqs HIGH 7.8
CVE-2023-45205

A vulnerability has been identified in SICAM PAS/PQS (All versions >= V8.00 < V8.20). The affected application is installed with specific files and f…

Fix: 8.20+
Fix from $1,950 2023-10-10
Sinec Nms HIGH 7.8
CVE-2022-30527

A vulnerability has been identified in SINEC NMS (All versions < V2.0). The affected application assigns improper access rights to specific folders c…

Fix: 2.0+
Fix from $1,950 2023-10-10
Mini Smart Wi Fi Plug Firmware HIGH 7.5
CVE-2023-42189

Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip …

Mitigation only
Fix from $1,950 2023-10-10
Debian Linux MEDIUM 5.3
CVE-2023-45364

An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision exis…

Fix: 1.39.5+
Fix from $1,600 2023-10-09
Decidim HIGH 7.1
CVE-2023-36465

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline p…

Fix: 0.26.8 / 0.27.4+
Fix from $1,950 2023-10-06
Gradle MEDIUM 6.5
CVE-2023-44387

Gradle is a build tool with a focus on build automation and support for multi-language development. When copying or archiving symlinked files, Gradle…

Fix: 7.6.3 / 8.4.0+
Fix from $1,600 2023-10-05
Vault HIGH 7.5
CVE-2023-5077

The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating …

Fix: 1.13.0+
Fix from $1,950 2023-09-29
Sd Wan Manager HIGH 8.8
CVE-2023-20254

A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attac…

Fix: 20.6.3.4 / 20.9.3.2+
Fix from $1,950 2023-09-27
Emui MEDIUM 5.3
CVE-2023-4565

Broadcast permission control vulnerability in the framework module. Successful exploitation of this vulnerability may cause the hotspot feature to be…

Mitigation only
Fix from $1,600 2023-09-27
Emui MEDIUM 5.3
CVE-2023-41295

Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerability may cause the screen to tu…

Mitigation only
Fix from $1,600 2023-09-25
Connect HIGH 8.8
CVE-2023-4665

Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: b…

Fix: 9.0+
Fix from $1,950 2023-09-15
Spectrum Power 7 HIGH 7.8
CVE-2023-38557

A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper access rights to the update scr…

Fix: 23q3+
Fix from $1,950 2023-09-14
Businessobjects Business Intelligence CRITICAL 9.9
CVE-2023-40622

SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attack…

Mitigation only
Fix from $2,300 2023-09-12
Node.js MEDIUM 5.3
CVE-2023-32005

A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used…

Fix: 20.5.1+
Fix from $1,600 2023-09-12
Driver HIGH 7.8
CVE-2023-32162

Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to esca…

Mitigation only
Fix from $1,950 2023-09-06
GitLab HIGH 7.2
CVE-2023-3915

An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all…

Fix: 16.1.5 / 16.2.5+
Fix from $1,950 2023-09-01
Sel 5033 Acselerator Real Time Automation Controller MEDIUM 5.5
CVE-2023-34391

Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/M…

Fix: 1.35.151.21000+
Fix from $1,600 2023-08-31
Car Rental Script HIGH 8.8
CVE-2023-40754

In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attacker…

Mitigation only
Fix from $1,950 2023-08-28
Firepower 9300 Firmware MEDIUM 6.3
CVE-2023-20200

A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security…

Fix: 4.1 / 4.2+
Fix from $1,600 2023-08-23
Application Policy Infrastructure Controller MEDIUM 5.4
CVE-2023-20230

A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenti…

Fix: 5.2 / 6.0+
Fix from $1,600 2023-08-23
Firepower Extensible Operating System MEDIUM 6.0
CVE-2023-20234

A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to create a file or overwrite any file on the filesyst…

Mitigation only
Fix from $1,600 2023-08-23
Escan Anti Virus HIGH 7.8
CVE-2023-4383

A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affects an unknown part of the file…

No fix yet
Fix from $1,950 2023-08-16
Raid Controller Web Interface HIGH 7.5
CVE-2023-4332

Broadcom RAID Controller web interface is vulnerable due to Improper permissions on the log file

Mitigation only
Fix from $1,950 2023-08-15
Oneapi Math Kernel Library HIGH 7.8
CVE-2023-28658

Insecure inherited permissions in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalatio…

Fix: 2022.0+
Fix from $1,950 2023-08-11
Opnsense CRITICAL 9.8
CVE-2023-39004

Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attac…

Fix: 23.7+
Fix from $2,300 2023-08-09