Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Powerscale Onefs HIGH 7.8
CVE-2021-21567

Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and…

Patch available
Fix from $1,950 2021-08-10
True Image HIGH 7.8
CVE-2021-32577

Acronis True Image prior to 2021 Update 5 for Windows allowed local privilege escalation due to insecure folder permissions.

Mitigation only
Fix from $1,950 2021-08-05
Chrome HIGH 7.8
CVE-2021-30577

Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation …

Fix: 92.0.4515.107+
Fix from $1,950 2021-08-03
Apex One HIGH 7.8
CVE-2021-32463

An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS), Worry-Free Business Securit…

Patch available
Fix from $1,950 2021-07-20
Fedora MEDIUM 6.3
CVE-2021-32760

containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted c…

Fix: 1.4.8 / 1.5.4+
Fix from $1,600 2021-07-19
G2 Driver HIGH 7.8
CVE-2021-35449

The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and be…

Fix: after 4.2.1.0
Fix from $1,950 2021-07-19
Rancher HIGH 8.8
CVE-2021-25318

A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have…

Fix: 2.4.16 / 2.5.9+
Fix from $1,950 2021-07-15
Safeq HIGH 7.8
CVE-2021-31859

Incorrect privileges in the MU55 FlexiSpooler service in YSoft SafeQ 6 6.0.55 allows local user privilege escalation by overwriting the executable fi…

Mitigation only
Fix from $1,950 2021-07-14
Android HIGH 7.8
CVE-2020-0417

In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to…

Patch available
Fix from $1,950 2021-07-14
Cloud Pak For Applications HIGH 8.8
CVE-2021-20423

IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper application permissions. IBM X-Force …

Fix: 4.3.1+
Fix from $1,950 2021-07-13
Simatic Pcs 7 Firmware HIGH 8.8
CVE-2021-31894

A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All …

Fix: 5.4 / 5.7+
Fix from $1,950 2021-07-13
Node.js HIGH 7.8
CVE-2021-22921EPSS 7%

Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More s…

Fix: 1.0.1.1 / 12.22.2+
Fix from $1,950 2021-07-12
Winwaste.net HIGH 7.8
CVE-2021-34110

WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file tha…

No fix yet
Fix from $1,950 2021-07-08
Guardium Data Encryption MEDIUM 5.3
CVE-2021-20416

IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set th…

Patch available
Fix from $1,600 2021-07-07
Storage Manager MEDIUM 6.5
CVE-2021-32526

Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary…

Fix: after 3.3.1
Fix from $1,600 2021-07-07
Xwiki MEDIUM 5.4
CVE-2021-32729

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability exists in versions prior to …

Fix: 12.6.8 / 12.10.4+
Fix from $1,600 2021-07-01
Enterprise Runtime For R HIGH 7.8
CVE-2021-23275

The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server …

Fix: after 11.3.0
Fix from $1,950 2021-06-29
Shopware HIGH 7.5
CVE-2021-32717

Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the h…

Fix: 6.4.1.1+
Fix from $1,950 2021-06-24
Db2 HIGH 8.1
CVE-2020-4945

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper …

Patch available
Fix from $1,950 2021-06-24
Android MEDIUM 5.5
CVE-2021-0552

In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local inf…

Mitigation only
Fix from $1,600 2021-06-22
Android HIGH 7.8
CVE-2021-0570

In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead …

Mitigation only
Fix from $1,950 2021-06-22
Android MEDIUM 5.5
CVE-2021-0572

In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local infor…

Mitigation only
Fix from $1,600 2021-06-22
Defibrillator Dashboard HIGH 7.8
CVE-2021-27483

ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to…

Fix: 2.2+
Fix from $1,950 2021-06-16
Android HIGH 7.8
CVE-2021-0477

In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could …

Patch available
Fix from $1,950 2021-06-11
Android MEDIUM 5.5
CVE-2021-25393

Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system ui…

No fix yet
Fix from $1,600 2021-06-11
Big Ip Access Policy Manager HIGH 7.8
CVE-2021-23022

On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak fil…

Fix: 7.2.1.3+
Fix from $1,950 2021-06-10
Lapqc71a Firmware HIGH 7.8
CVE-2021-0055

Insecure inherited permissions for some Intel(R) NUC 9 Extreme Laptop Kit LAN Drivers before version 10.42 may allow an authenticated user to potenti…

Fix: 10.42+
Fix from $1,950 2021-06-09
Lapbc510 Firmware HIGH 7.8
CVE-2021-0056

Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to…

Fix: 1.1+
Fix from $1,950 2021-06-09
Vtune Profiler HIGH 7.8
CVE-2021-0077

Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before version 2021.1.1 may allow an authenticated user to potent…

Fix: 2021.1.1+
Fix from $1,950 2021-06-09
Unite HIGH 7.8
CVE-2021-0102

Insecure inherited permissions in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enabl…

Fix: 4.2.25031+
Fix from $1,950 2021-06-09