Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Ac 9461 Firmware HIGH 7.3
CVE-2021-0105

Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an authenticated user to potentially enable information disclo…

Fix: 22.0+
Fix from $1,950 2021-06-09
Openshift Virtualization HIGH 7.0
CVE-2020-1742

An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the containe…

Fix: 2.3.0+
Fix from $1,950 2021-06-07
Maximum Security 2021 HIGH 7.8
CVE-2021-32460

The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could a…

Mitigation only
Fix from $1,950 2021-06-03
Satellite MEDIUM 5.5
CVE-2020-14335

A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows…

Mitigation only
Fix from $1,600 2021-06-02
Nginx Controller MEDIUM 5.5
CVE-2021-23021

The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to…

Fix: 3.7.0+
Fix from $1,600 2021-06-01
Kubevirt MEDIUM 6.5
CVE-2020-1701

A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access t…

Fix: 0.26.0+
Fix from $1,600 2021-05-27
Umask HIGH 7.8
CVE-2021-31155

Failure to normalize the umask in please before 0.4 allows a local attacker to gain full root privileges if they are allowed to execute at least one …

Fix: 0.4+
Fix from $1,950 2021-05-27
Fusion HIGH 8.8
CVE-2020-28909EPSS 5%

Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges use…

Fix: after 4.1.8
Fix from $1,950 2021-05-24
Nagios Xi CRITICAL 9.8
CVE-2020-28910

Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, …

Fix: after 5.7.5
Fix from $2,300 2021-05-24
Plone CRITICAL 9.9
CVE-2021-33509

Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Pyt…

Fix: after 5.2.4
Fix from $2,300 2021-05-21
Orion Job Scheduler HIGH 8.8
CVE-2021-31475EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authe…

Mitigation only
Fix from $1,950 2021-05-21
Remedy Mid Tier HIGH 8.8
CVE-2017-17677

BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to ru…

Mitigation only
Fix from $1,950 2021-05-19
Rabbitmq Server HIGH 7.8
CVE-2021-22117

RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient loc…

Fix: 3.8.16+
Fix from $1,950 2021-05-18
0852 0303 Firmware MEDIUM 5.3
CVE-2021-20996

In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.

Fix: after 1.2.3.s0
Fix from $1,600 2021-05-13
Windows 10 HIGH 7.8
CVE-2021-31167

Windows Container Manager Service Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-05-11
Teamcity MEDIUM 5.3
CVE-2021-31907

In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.

Fix: 2020.2.2+
Fix from $1,600 2021-05-11
Youtrack HIGH 7.5
CVE-2021-31902

In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.

Fix: 2020.6.6600+
Fix from $1,950 2021-05-11
Openemr HIGH 8.2
CVE-2021-32101

The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerab…

Mitigation only
Fix from $1,950 2021-05-07
Openstack HIGH 7.5
CVE-2021-31918

A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update a…

Mitigation only
Fix from $1,950 2021-05-06
Btcpay Server MEDIUM 5.3
CVE-2021-29247

BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.

Fix: after 1.0.7.0
Fix from $1,600 2021-05-05
MongoDB MEDIUM 6.5
CVE-2021-20326

A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior …

Fix: 4.4.4+
Fix from $1,600 2021-04-30
701client HIGH 8.8
CVE-2021-28269

Soyal Technology 701Client 9.0.1 is vulnerable to Insecure permissions via client.exe binary with Authenticated Users group with Full permissions.

No fix yet
Fix from $1,950 2021-04-27
Webaccess\/scada HIGH 8.8
CVE-2021-22669

Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, whic…

Fix: after 9.0.1
Fix from $1,950 2021-04-26
Streaming Engine HIGH 7.1
CVE-2021-31540

Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regu…

Fix: after 4.8.5
Fix from $1,950 2021-04-23
Controller HIGH 7.5
CVE-2020-27568

Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. …

Mitigation only
Fix from $1,950 2021-04-21
Counteract HIGH 7.8
CVE-2021-28098

An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureCo…

Fix: 8.1.4+
Fix from $1,950 2021-04-14
C Bus Toolkit HIGH 7.8
CVE-2021-22716

A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged use…

Fix: after 1.15.7
Fix from $1,950 2021-04-13
Apex One HIGH 7.8
CVE-2021-25250

An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could a…

No fix yet
Fix from $1,950 2021-04-13
Apex One HIGH 7.8
CVE-2021-25253

An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the s…

Mitigation only
Fix from $1,950 2021-04-13
Apex One HIGH 7.8
CVE-2021-28645

An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to…

Mitigation only
Fix from $1,950 2021-04-13