Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Openjdk HIGH 7.8
CVE-2021-20264

An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with acces…

Mitigation only
Fix from $1,950 2021-10-06
Android HIGH 7.8
CVE-2021-0692

In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIntent. This could lead to loca…

Patch available
Fix from $1,950 2021-10-06
Fedora MEDIUM 6.3
CVE-2021-41091

Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data director…

Fix: 20.10.9+
Fix from $1,600 2021-10-04
Multipass HIGH 7.8
CVE-2021-3747

The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner.

Fix: 1.7.2+
Fix from $1,950 2021-10-01
Meetings HIGH 7.8
CVE-2021-34409

It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.…

Fix: 5.1.0 / 5.2.0+
Fix from $1,950 2021-09-27
Zoom Plugin For Microsoft Outlook HIGH 7.8
CVE-2021-34410

A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook for Mac before 5.0.25611.052…

Fix: 5.0.25611.0521+
Fix from $1,950 2021-09-27
Mobility MEDIUM 5.3
CVE-2021-40066

The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and vali…

Fix: 11.76 / 12.14+
Fix from $1,600 2021-09-16
Mobility MEDIUM 6.8
CVE-2021-40067

The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manual…

Fix: 12.14+
Fix from $1,600 2021-09-16
Glpi MEDIUM 6.5
CVE-2021-39210

GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses …

Fix: 9.5.6+
Fix from $1,600 2021-09-15
Enterprise Search HIGH 8.8
CVE-2021-22149

Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate rou…

Fix: 7.14.0+
Fix from $1,950 2021-09-15
Visual Studio 2017 HIGH 7.8
CVE-2021-26434

Visual Studio Elevation of Privilege Vulnerability

Fix: after 16.11
Fix from $1,950 2021-09-15
Elasticsearch MEDIUM 6.5
CVE-2021-22147

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining…

Fix: 7.14.0+
Fix from $1,600 2021-09-15
Enterprise Search HIGH 8.8
CVE-2021-22148

Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their cre…

Fix: 7.14.0+
Fix from $1,950 2021-09-15
Web Interface HIGH 7.5
CVE-2021-3706

adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag

Fix: 5.6+
Fix from $1,950 2021-09-15
Aquariusnet HIGH 8.8
CVE-2021-35508

NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges via a low-privileged user accou…

No fix yet
Fix from $1,950 2021-09-01
Indexhibit HIGH 8.8
CVE-2020-18121

A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.

No fix yet
Fix from $1,950 2021-08-30
Unclassified HIGH 7.5
CVE-2021-38154

Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, a…

No fix yet
Fix from $1,950 2021-08-29
Ipados MEDIUM 5.5
CVE-2021-30964

An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPad…

Fix: 8.3 / 12.1+
Fix from $1,600 2021-08-24
macOS MEDIUM 5.5
CVE-2021-30920

A permissions issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.0.1. A local attacker may be able to read sensit…

Fix: 12.0.1+
Fix from $1,600 2021-08-24
Mac Os X MEDIUM 5.5
CVE-2021-30892EPSS 10%

An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Cat…

Fix: 10.15.7 / 11.6.1+
Fix from $1,600 2021-08-24
Raspap HIGH 8.8
CVE-2021-38557

raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can exec…

No fix yet
Fix from $1,950 2021-08-24
Yandex Browser HIGH 7.8
CVE-2021-25263

Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code wit…

Fix: 21.9.0.390+
Fix from $1,950 2021-08-17
Emc Powerscale Onefs HIGH 7.8
CVE-2021-36279

Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a u…

Fix: after 9.2.2.0
Fix from $1,950 2021-08-16
Emc Powerscale Onefs MEDIUM 5.5
CVE-2021-36280

Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a u…

Fix: after 9.2.1
Fix from $1,600 2021-08-16
Emc Powerscale Onefs HIGH 8.8
CVE-2021-36281

Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privileged authenticated user can po…

Fix: after 9.2.1
Fix from $1,950 2021-08-16
Desktop HIGH 7.8
CVE-2021-37841

Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows conta…

Fix: 3.6.0+
Fix from $1,950 2021-08-12
Cpanel MEDIUM 5.5
CVE-2021-38590

In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584).

Fix: 11.98.0.8+
Fix from $1,600 2021-08-11
Sapphireims HIGH 8.8
CVE-2017-16630

In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installed, because of an Insecure Dir…

Mitigation only
Fix from $1,950 2021-08-11
Sapphireims MEDIUM 6.5
CVE-2017-16631

In SapphireIMS 4097_1, a guest user is able to change the password of an administrative user by utilizing an Insecure Direct Object Reference (IDOR) …

Mitigation only
Fix from $1,600 2021-08-11
Pixma Tr150 Firmware HIGH 7.8
CVE-2021-38085

The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can ov…

Fix: after 3.71.2.10
Fix from $1,950 2021-08-11