Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Xpedition Designer HIGH 7.8
CVE-2022-31465

A vulnerability has been identified in Xpedition Designer VX.2.10 (All versions < VX.2.10 Update 13), Xpedition Designer VX.2.11 (All versions < VX.2…

Mitigation only
Fix from $1,950 2022-06-14
Connx MEDIUM 6.5
CVE-2021-40649

In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.

No fix yet
Fix from $1,600 2022-06-14
Basic Pdu Firmware CRITICAL 9.8
CVE-2022-33175

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field t…

Fix: 3.30.30+
Fix from $2,300 2022-06-13
Log Wp Mail HIGH 7.5
CVE-2022-1412

The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filenames, allowing any unauthenti…

Fix: after 0.1
Fix from $1,950 2022-06-13
On Premise HIGH 7.5
CVE-2022-25151

Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failu…

Fix: 6.35.37347.20040+
Fix from $1,950 2022-06-09
Apex One HIGH 7.8
CVE-2022-30700

An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with es…

Fix: 14.0.10349+
Fix from $1,950 2022-05-27
Fedora MEDIUM 6.5
CVE-2022-1348

A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances …

Fix: 3.20.0+
Fix from $1,600 2022-05-25
Cyber Protect HIGH 7.5
CVE-2022-30990

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before bui…

Fix: 15+
Fix from $1,950 2022-05-18
Ir302 Firmware MEDIUM 6.1
CVE-2022-25172

An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session c…

Fix: after 3.5.4
Fix from $1,600 2022-05-12
Zonealarm HIGH 7.8
CVE-2022-23743

Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permiss…

Fix: 15.8.211.192119+
Fix from $1,950 2022-05-11
Forticlient HIGH 7.5
CVE-2021-44167

An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6…

Fix: after 7.0.2
Fix from $1,950 2022-05-11
Bigfix Webui MEDIUM 6.5
CVE-2021-27764

Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)

Mitigation only
Fix from $1,600 2022-05-06
Access Policy Manager Clients HIGH 7.8
CVE-2022-29263

On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…

Mitigation only
Fix from $1,950 2022-05-05
Benchmark Programming Tool HIGH 7.3
CVE-2022-22521

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users priv…

Fix: 1.2.72+
Fix from $1,950 2022-04-27
Nginx Ingress Controller MEDIUM 6.5
CVE-2021-23055

On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not appl…

Fix: 1.12.3 / 2.0.3+
Fix from $1,600 2022-04-21
Shopware HIGH 8.1
CVE-2022-24872

Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable with…

Fix: 6.4.10.1+
Fix from $1,950 2022-04-20
Roboguide MEDIUM 5.7
CVE-2021-38483

The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileges access to overwrite the bi…

Fix: after 9.40083.00.05
Fix from $1,600 2022-04-20
Amazon Ssm Agent HIGH 7.0
CVE-2022-29527

Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate p…

Fix: 3.1.1208.0+
Fix from $1,950 2022-04-20
Cloud Foundation HIGH 7.8
CVE-2022-22960 KEVEPSS 36%

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in sup…

Fix: 5.0 / 9.0+
Fix from $1,950 2022-04-13
Simatic Energy Manager Basic HIGH 7.8
CVE-2022-23448

A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 U…

Fix: 7.3+
Fix from $1,950 2022-04-12
Zerotierone HIGH 7.8
CVE-2022-1316

Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation

Fix: 1.8.8+
Fix from $1,950 2022-04-11
Zyxel Ap Configurator HIGH 7.8
CVE-2022-0556

A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1…

Mitigation only
Fix from $1,950 2022-04-11
Emc Unity Operating Environment MEDIUM 6.7
CVE-2021-36290

Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vuln…

Fix: after 8.1.21.266
Fix from $1,600 2022-04-08
Control Rte Sl HIGH 7.8
CVE-2022-22516

The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory spac…

Fix: 3.5.18.0+
Fix from $1,950 2022-04-07
Synaman HIGH 7.8
CVE-2022-26250

Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges.

Fix: after 5.1
Fix from $1,950 2022-04-06
Bigant Server HIGH 7.5
CVE-2022-26281

BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.

No fix yet
Fix from $1,950 2022-04-05
Ruoyi MEDIUM 6.5
CVE-2022-23869

In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be res…

No fix yet
Fix from $1,600 2022-03-30
Salt HIGH 8.8
CVE-2022-22941

An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if…

Fix: 3002.8 / 3003.4+
Fix from $1,950 2022-03-29
Fedora MEDIUM 5.9
CVE-2022-24769

Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to…

Fix: 1.1.2 / 20.10.14+
Fix from $1,600 2022-03-24
Unified Threat Management HIGH 7.8
CVE-2022-0652

Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to…

Fix: 9.710+
Fix from $1,950 2022-03-22