Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Vantara Pentaho Business Analytics Server HIGH 8.8
CVE-2022-43773EPSS 22%

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data sourc…

Fix: 9.3.0.2+
Fix from $1,950 2023-04-03
Robodk HIGH 7.8
CVE-2023-1516

RoboDK versions 5.5.3 and prior contain an insecure permission assignment to critical directories vulnerability, which could allow a local user to …

Fix: after 5.5.3
Fix from $1,950 2023-03-28
Nextcloud Server HIGH 8.1
CVE-2023-25817

Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions …

Fix: 24.0.9+
Fix from $1,950 2023-03-27
Infrasuite Device Master HIGH 7.8
CVE-2023-1135

In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in l…

Fix: 1.0.5+
Fix from $1,950 2023-03-27
Hippo4j MEDIUM 6.5
CVE-2023-27096

Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information via the ConfigVerifyController …

No fix yet
Fix from $1,600 2023-03-27
Openstack MEDIUM 5.5
CVE-2022-3146

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Openstack MEDIUM 5.5
CVE-2022-3101

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Dreamer Cms MEDIUM 5.3
CVE-2023-27084

Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information via the AttachmentController…

No fix yet
Fix from $1,600 2023-03-16
Hippo4j MEDIUM 6.5
CVE-2023-27095

Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserControl…

Fix: 1.4.3+
Fix from $1,600 2023-03-16
Azure Setup Kubectl HIGH 7.0
CVE-2023-23939

Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creat…

Fix: 3.0+
Fix from $1,950 2023-03-06
Clash CRITICAL 9.8
CVE-2023-24205

Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration…

No fix yet
Fix from $2,300 2023-02-23
Php Fusion HIGH 8.1
CVE-2021-3172

An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature.

Fix: 9.10.00+
Fix from $1,950 2023-02-17
Oneapi Cli HIGH 7.8
CVE-2022-25992

Insecure inherited permissions in the Intel(R) oneAPI Toolkits oneapi-cli before version 0.2.0 may allow an authenticated user to potentially enable …

Fix: 0.2.0+
Fix from $1,950 2023-02-16
Metasys System Configuration Tool MEDIUM 6.1
CVE-2022-21939

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 …

Fix: 14.2.3 / 15.0.3+
Fix from $1,600 2023-02-09
Richdocuments MEDIUM 5.7
CVE-2023-25150

Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to …

Fix: 3.8.7 / 4.2.9+
Fix from $1,600 2023-02-08
Jeecg HIGH 7.5
CVE-2021-37304

An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information …

Fix: after 2.4.5
Fix from $1,950 2023-02-03
Jeecg HIGH 7.5
CVE-2021-37305

An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via …

Fix: after 2.4.5
Fix from $1,950 2023-02-03
Jeecg HIGH 7.5
CVE-2021-37306

An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via …

Fix: after 2.4.5
Fix from $1,950 2023-02-03
Apc Easy Ups Online Monitoring Software HIGH 7.8
CVE-2022-42972

A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attack…

Fix: 2.5-ga / 2.5-gs+
Fix from $1,950 2023-02-01
Ngeniusone HIGH 8.8
CVE-2022-44715

Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.

Mitigation only
Fix from $1,950 2023-01-27
Sidexis HIGH 7.8
CVE-2022-44263

Dentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control.

Fix: after 4.3
Fix from $1,950 2023-01-26
Glpi MEDIUM 6.5
CVE-2023-23610

GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any use…

Fix: 9.5.12 / 10.0.6+
Fix from $1,600 2023-01-26
Android MEDIUM 5.5
CVE-2023-20923

In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to a permissions bypass. This c…

Mitigation only
Fix from $1,600 2023-01-26
Robotic Process Automation For Cloud Pak HIGH 7.8
CVE-2023-22592

IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permi…

Fix: 21.0.5+
Fix from $1,950 2023-01-18
Command\|configure HIGH 7.8
CVE-2022-34457

Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path whi…

Fix: 4.9.0+
Fix from $1,950 2023-01-18
Eternal Terminal MEDIUM 5.3
CVE-2022-48257

In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.

Patch available
Fix from $1,600 2023-01-13
Bv 10 Firmware MEDIUM 5.5
CVE-2022-39186

EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions

Mitigation only
Fix from $1,600 2023-01-12
Fedora MEDIUM 5.5
CVE-2022-47927

An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existin…

Fix: 1.35.9 / 1.38.5+
Fix from $1,600 2023-01-12
Daloradius MEDIUM 5.3
CVE-2022-4630

Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.

Patch available
Fix from $1,600 2022-12-21
Subsites HIGH 7.5
CVE-2022-42949

Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.

Fix: after 2.6.0
Fix from $1,950 2022-12-21