Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Android MEDIUM 5.5
CVE-2022-20399

In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default value. This could lead to loc…

Patch available
Fix from $1,600 2022-09-13
Onedev MEDIUM 5.4
CVE-2022-39207

Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retriev…

Fix: 7.3.0+
Fix from $1,600 2022-09-13
Talos Linux HIGH 8.8
CVE-2022-36103

Talos Linux is a Linux distribution built for Kubernetes deployments. Talos worker nodes use a join token to get accepted into the Talos cluster. Due…

Fix: 1.2.2+
Fix from $1,950 2022-09-13
Endpoint MEDIUM 6.7
CVE-2022-36670

PCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges t…

Fix: 5.17.470+
Fix from $1,600 2022-09-06
Malware Fighter MEDIUM 6.7
CVE-2022-37771

IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify pr…

No fix yet
Fix from $1,600 2022-09-06
Shenyu HIGH 8.8
CVE-2022-37435

Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This i…

Patch available
Fix from $1,950 2022-09-01
Avideo HIGH 7.5
CVE-2022-32777

An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and…

Mitigation only
Fix from $1,950 2022-08-22
Avideo HIGH 7.5
CVE-2022-32778

An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and…

Mitigation only
Fix from $1,950 2022-08-22
Openshift Container Platform CRITICAL 9.8
CVE-2020-27836

A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker…

Patch available
Fix from $2,300 2022-08-22
Cloud Print Management HIGH 8.8
CVE-2022-35167

Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.

Mitigation only
Fix from $1,950 2022-08-19
Spectrum Scale Data Access Services MEDIUM 6.5
CVE-2022-22411

IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate c…

Patch available
Fix from $1,600 2022-08-10
Twinsoft CRITICAL 9.8
CVE-2021-22648

Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.

Fix: 1.46 / 12.4+
Fix from $2,300 2022-07-28
Dataease MEDIUM 6.5
CVE-2022-34112

An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normall…

No fix yet
Fix from $1,600 2022-07-22
Openstack MEDIUM 6.5
CVE-2022-1655

An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without …

Mitigation only
Fix from $1,600 2022-07-22
Parallels Desktop HIGH 7.8
CVE-2022-34891

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker…

No fix yet
Fix from $1,950 2022-07-18
Sage 300 HIGH 7.8
CVE-2021-45492

In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-w…

Fix: after 2022
Fix from $1,950 2022-07-14
Android HIGH 7.5
CVE-2022-20234

In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, it gets both 'mComponentName'…

Patch available
Fix from $1,950 2022-07-13
Android HIGH 7.8
CVE-2022-20218

In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic error in the code. This could le…

Mitigation only
Fix from $1,950 2022-07-13
Android HIGH 7.8
CVE-2022-33695

Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.

Mitigation only
Fix from $1,950 2022-07-12
Novaicare HIGH 8.8
CVE-2021-38289

An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate…

No fix yet
Fix from $1,950 2022-07-12
Mini Tmall HIGH 8.8
CVE-2022-30929

Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.

No fix yet
Fix from $1,950 2022-07-06
Openshift Origin Node Util MEDIUM 5.5
CVE-2014-0068

It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.

Mitigation only
Fix from $1,600 2022-06-30
Pingid Integration For Windows Login MEDIUM 5.5
CVE-2022-23725

PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circu…

Fix: 2.8+
Fix from $1,600 2022-06-30
Nomachine HIGH 7.3
CVE-2022-34043

Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perform a DLL hijacking attack an…

No fix yet
Fix from $1,950 2022-06-29
Jazz Team Server MEDIUM 5.3
CVE-2021-38879

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se…

Patch available
Fix from $1,600 2022-06-24
Jazz Team Server MEDIUM 5.3
CVE-2021-20355

IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se…

Patch available
Fix from $1,600 2022-06-24
Oneblog MEDIUM 6.5
CVE-2022-34012

Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privilege…

No fix yet
Fix from $1,600 2022-06-23
Rex640 Pcl1 Firmware MEDIUM 6.5
CVE-2022-1596

Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to …

Fix: 1.1.4 / 1.2.1+
Fix from $1,600 2022-06-21
Protect HIGH 7.8
CVE-2022-31464

Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing the service binary path.

No fix yet
Fix from $1,950 2022-06-16
Splunk HIGH 7.5
CVE-2022-32155

In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential expos…

Fix: 8.2.2106 / 9.0+
Fix from $1,950 2022-06-15