Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Sharepoint Enterprise Server HIGH 8.8
CVE-2021-42309

Microsoft SharePoint Server Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-12-15
Fortinac HIGH 7.8
CVE-2021-43065

A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows a…

Fix: 8.8.10 / 9.1.4+
Fix from $1,950 2021-12-09
Op Tee HIGH 7.1
CVE-2021-36133

The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the No…

Mitigation only
Fix from $1,950 2021-12-07
Tmate Ssh Server HIGH 7.0
CVE-2021-44512

World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of sessi…

Fix: after 2.3.0
Fix from $1,950 2021-12-07
Unitrends Backup HIGH 7.8
CVE-2021-43034

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as th…

Fix: 10.5.5+
Fix from $1,950 2021-12-06
Ehrd HIGH 8.8
CVE-2021-43359

Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a …

Mitigation only
Fix from $1,950 2021-12-01
Concrete Cms HIGH 7.2
CVE-2021-40101

An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

Fix: 8.5.7+
Fix from $1,950 2021-11-30
Burp Suite MEDIUM 6.5
CVE-2021-44230

PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privi…

Fix: after 2021.11
Fix from $1,600 2021-11-30
Vault MEDIUM 6.5
CVE-2021-43998

HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multipl…

Fix: after 1.7.5
Fix from $1,600 2021-11-30
Topease CRITICAL 9.1
CVE-2021-42115

Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated re…

Fix: after 7.1.27
Fix from $2,300 2021-11-30
Download Plugin MEDIUM 5.7
CVE-2021-24703

The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any aut…

Fix: 1.6.1+
Fix from $1,600 2021-11-23
Creative Cloud Desktop Application HIGH 7.8
CVE-2021-43019

Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe servi…

Fix: after 5.5
Fix from $1,950 2021-11-23
Ozone MEDIUM 6.5
CVE-2021-39235

In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block to…

Fix: 1.2.0+
Fix from $1,600 2021-11-19
Ax210 Firmware HIGH 7.8
CVE-2021-0064

Insecure inherited permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated…

Fix: 22.40+
Fix from $1,950 2021-11-17
Nuc M15 Laptop Kit Audio Driver Pack HIGH 7.8
CVE-2021-33091

Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit audio driver pack before version 1.3 may allow an authenticated u…

Fix: 1.3+
Fix from $1,950 2021-11-17
Nuc M15 Laptop Kit Serial Io Driver Pack HIGH 7.8
CVE-2021-33093

Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Serial IO driver pack before version 30.100.2104.1 may allow an a…

Fix: 30.100.2104.1+
Fix from $1,950 2021-11-17
Nuc M15 Laptop Kit Keyboard Led Service Driver Pack HIGH 7.8
CVE-2021-33094

Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow…

Fix: 1.0.0.4+
Fix from $1,950 2021-11-17
Manageengine Remote Access Plus HIGH 7.8
CVE-2021-42954

Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is v…

Fix: 10.1.2121.1+
Fix from $1,950 2021-11-17
Manageengine Remote Access Plus HIGH 7.8
CVE-2021-42955

Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because…

Fix: 10.1.2132+
Fix from $1,950 2021-11-17
Security Siteprotector System MEDIUM 5.3
CVE-2020-4146

IBM Security SiteProtector System 3.1.1 could allow a remote attacker to obtain sensitive information, caused by missing 'HttpOnly' flag. A remote at…

Mitigation only
Fix from $1,600 2021-11-12
Sentron Powermanager 3 HIGH 7.8
CVE-2021-37207

A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific …

Fix: after 3.6
Fix from $1,950 2021-11-09
Neoan3 Template CRITICAL 9.8
CVE-2021-41170

neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template eng…

Fix: 1.1.1+
Fix from $2,300 2021-11-08
Planning Analytics MEDIUM 5.3
CVE-2021-20526

IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote at…

Patch available
Fix from $1,600 2021-10-27
Build Cache Node CRITICAL 9.8
CVE-2021-41589

In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when r…

Fix: 10.0 / 2021.3+
Fix from $2,300 2021-10-27
Openclinic Ga HIGH 7.8
CVE-2021-37364

OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/…

No fix yet
Fix from $1,950 2021-10-26
Nagios Xi HIGH 7.8
CVE-2021-40343

An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileg…

No fix yet
Fix from $1,950 2021-10-26
Versiondog HIGH 8.8
CVE-2021-38475

The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions.

Fix: 8.0.0+
Fix from $1,950 2021-10-22
Junos MEDIUM 5.5
CVE-2021-31377

An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the filesystem of Junos OS allows a local authenticated a…

Mitigation only
Fix from $1,600 2021-10-19
Superdome Flex Firmware MEDIUM 6.1
CVE-2021-26589

A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Si…

Fix: 3.40.106+
Fix from $1,600 2021-10-19
Vault MEDIUM 5.4
CVE-2021-41802

HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with…

Fix: 1.7.5 / 1.8.4+
Fix from $1,600 2021-10-08