Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Star Ccm\+ HIGH 7.8
CVE-2022-43517

A vulnerability has been identified in Simcenter STAR-CCM+ (All versions < V2306). The affected application improperly assigns file permissions to in…

Mitigation only
Fix from $1,950 2022-12-13
Otcp Firmware MEDIUM 6.5
CVE-2022-23143

ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions…

Fix: 2.21.40.06+
Fix from $1,600 2022-12-05
Debian Linux MEDIUM 6.5
CVE-2022-46338

g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writabl…

Patch available
Fix from $1,600 2022-11-30
Talk MEDIUM 5.5
CVE-2022-41926

Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the receiver is not protected by broa…

Fix: 14.1.0+
Fix from $1,600 2022-11-25
Local Discovery Server HIGH 7.8
CVE-2022-44725

OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to cr…

Fix: 1.04.405.479+
Fix from $1,950 2022-11-17
Cbrn Analysis HIGH 8.8
CVE-2022-45193

CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privilege escalation.

Fix: 22+
Fix from $1,950 2022-11-12
Cyber Protect Home Office MEDIUM 5.5
CVE-2022-44746

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows)…

Fix: 40107+
Fix from $1,600 2022-11-07
Cyber Protect Home Office HIGH 7.8
CVE-2022-44732

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) befor…

Fix: 39900+
Fix from $1,950 2022-11-07
Cyber Protect Home Office HIGH 7.8
CVE-2022-44733

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) befor…

Fix: 39900+
Fix from $1,950 2022-11-07
Data Exchange Layer MEDIUM 5.5
CVE-2022-2188

Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak dir…

Fix: 6.0.0.280+
Fix from $1,600 2022-11-07
Workforce Access HIGH 8.8
CVE-2022-3258

Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse.

Fix: 7.7.1+
Fix from $1,950 2022-11-03
Ipados MEDIUM 5.5
CVE-2022-32929

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 15.7 and iPadOS 15.7, iOS 16…

Fix: 15.7+
Fix from $1,600 2022-11-01
Automox HIGH 7.8
CVE-2022-36122

The Automox Agent before 40 on Windows incorrectly sets permissions on key files.

Fix: 40+
Fix from $1,950 2022-10-21
Junos Os Evolved HIGH 7.3
CVE-2022-22248

An Incorrect Permission Assignment vulnerability in shell processing of Juniper Networks Junos OS Evolved allows a low-privileged local user to modif…

Mitigation only
Fix from $1,950 2022-10-18
Remisol Advance MEDIUM 5.5
CVE-2022-26238

The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged u…

Fix: after 2.0.12.1
Fix from $1,600 2022-10-06
Remisol Advance MEDIUM 5.5
CVE-2022-26236

The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-pri…

Fix: after 2.0.12.1
Fix from $1,600 2022-10-06
Aura Application Enablement Services MEDIUM 6.7
CVE-2022-2975

A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative us…

Fix: 8.1.3.5 / 10.1.0.2+
Fix from $1,600 2022-10-06
Remisol Advance MEDIUM 5.5
CVE-2022-26239

The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows unprivileged use…

Fix: after 2.0.12.1
Fix from $1,600 2022-10-06
Remisol Advance MEDIUM 6.5
CVE-2022-26240

The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged us…

Fix: after 2.0.12.1
Fix from $1,600 2022-10-06
Remisol Advance MEDIUM 5.5
CVE-2022-26237

The default privileges for the running service Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged us…

Fix: after 2.0.12.1
Fix from $1,600 2022-10-06
Psql HIGH 8.8
CVE-2022-40756

If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or…

Fix: 14.21.022 / 15.01.017+
Fix from $1,950 2022-09-30
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15328

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.

No fix yet
Fix from $1,600 2022-09-29
Cloudcnm Secumanager MEDIUM 5.3
CVE-2020-15329

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.

No fix yet
Fix from $1,600 2022-09-29
Airmedia HIGH 8.8
CVE-2022-40298

Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the Ai…

Mitigation only
Fix from $1,950 2022-09-23
Code By Zapier CRITICAL 9.9
CVE-2022-28802

Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScript code. In other words, Cod…

Fix: 2022-08-17+
Fix from $2,300 2022-09-21
Logcheck CRITICAL 9.8
CVE-2017-20148

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck us…

Fix: after 1.3.23
Fix from $2,300 2022-09-20
Cri O HIGH 7.1
CVE-2022-2995

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modifica…

Patch available
Fix from $1,950 2022-09-19
Softmaster HIGH 7.8
CVE-2022-2332

A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment.

Mitigation only
Fix from $1,950 2022-09-16
Control Desk MEDIUM 5.3
CVE-2022-22330

IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attack…

Mitigation only
Fix from $1,600 2022-09-13
Android HIGH 7.8
CVE-2022-20398

In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could le…

Patch available
Fix from $1,950 2022-09-13