Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Teamwork Management System MEDIUM 5.9
CVE-2022-26247

TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify t…

No fix yet
Fix from $1,600 2022-03-20
Anaconda3 HIGH 7.8
CVE-2022-26526

Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDA…

Fix: after 2021.11.0.0
Fix from $1,950 2022-03-17
Cscreen MEDIUM 5.3
CVE-2022-21946

A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local us…

Fix: after 1.3
Fix from $1,600 2022-03-16
Jetson Linux HIGH 7.6
CVE-2022-21819

NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physic…

Fix: 32.7.1+
Fix from $1,950 2022-03-11
Centum Cs 3000 Firmware HIGH 7.8
CVE-2022-22141

'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL configurat…

Mitigation only
Fix from $1,950 2022-03-11
Centum Cs 3000 Firmware HIGH 7.8
CVE-2022-22148

'Root Service' service implemented in the following Yokogawa Electric products creates some named pipe with improper ACL configuration. CENTUM CS 300…

Mitigation only
Fix from $1,950 2022-03-11
Steelcentral Appinternals Dynamic Sampling Agent HIGH 7.8
CVE-2021-42855

It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that c…

Fix: 11.8.8 / 12.13.0+
Fix from $1,950 2022-03-10
Antivirus Plus HIGH 7.8
CVE-2021-4199

Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Securit…

Fix: 7.4.3.146 / 26.0.3.29+
Fix from $1,950 2022-03-07
Libvirt MEDIUM 6.3
CVE-2021-3631

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access fil…

Fix: 7.5.0+
Fix from $1,600 2022-03-02
Stepmania CRITICAL 9.1
CVE-2022-25010

The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.

Fix: after 5.0.12
Fix from $2,300 2022-03-01
Hub HIGH 7.5
CVE-2022-24327

In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.

Fix: 2021.1.13890+
Fix from $1,950 2022-02-25
Fuchsia MEDIUM 5.5
CVE-2022-0247

An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO…

Fix: 2022-01-03+
Fix from $1,600 2022-02-25
Openshift Gitops MEDIUM 6.5
CVE-2021-3557

A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-serve…

Fix: 1.1.1+
Fix from $1,600 2022-02-16
Vss Doctor HIGH 7.8
CVE-2022-0483

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53

Mitigation only
Fix from $1,950 2022-02-11
Cassandra CRITICAL 9.1
CVE-2021-44521EPSS 55%

When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab…

Fix: 3.0.26 / 3.11.12+
Fix from $2,300 2022-02-11
Emui HIGH 7.8
CVE-2021-39992

There is an improper security permission configuration vulnerability on ACPU.Successful exploitation of this vulnerability may affect service confide…

No fix yet
Fix from $1,950 2022-02-09
Opc Server For Ac 800m HIGH 8.8
CVE-2021-22284

Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to execute arbitrary code in the nod…

Fix: 6.0.0-4+
Fix from $1,950 2022-02-04
Northstar Club Management CRITICAL 9.8
CVE-2021-29396

Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various function…

Mitigation only
Fix from $2,300 2022-02-04
Microweber MEDIUM 6.5
CVE-2022-0277

Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.

Fix: after 1.2.10
Fix from $1,600 2022-01-20
Onionshare MEDIUM 5.3
CVE-2022-21694

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The…

Fix: 2.5+
Fix from $1,600 2022-01-18
Fuchsia CRITICAL 9.8
CVE-2021-22566

An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged …

Patch available
Fix from $2,300 2022-01-18
Android HIGH 7.8
CVE-2021-39621

In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could le…

Mitigation only
Fix from $1,950 2022-01-14
Android HIGH 7.8
CVE-2021-39627

In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could le…

Mitigation only
Fix from $1,950 2022-01-14
Edgerover CRITICAL 9.1
CVE-2022-22988

File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for …

Fix: 1.5.0-576+
Fix from $2,300 2022-01-13
Fedora HIGH 7.3
CVE-2022-23132

During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix …

Fix: after 5.4.8
Fix from $1,950 2022-01-13
Genie Installer HIGH 7.8
CVE-2021-20172

All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of…

No fix yet
Fix from $1,950 2021-12-30
Bitmask Riseup Vpn HIGH 7.3
CVE-2021-44466

Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-defau…

Patch available
Fix from $1,950 2021-12-30
Groupsession HIGH 7.5
CVE-2021-20874

Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 …

Fix: after 5.1.1
Fix from $1,950 2021-12-24
Amegaview HIGH 7.8
CVE-2021-27445

Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges on the device.

Fix: after 3.0
Fix from $1,950 2021-12-21
Android MEDIUM 6.7
CVE-2021-0904

In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System…

Mitigation only
Fix from $1,600 2021-12-15