Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Apex One MEDIUM 5.5
CVE-2021-28646

An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to take …

Mitigation only
Fix from $1,600 2021-04-13
Block Safe Firmware HIGH 7.8
CVE-2020-26155

Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which …

Fix: after 4.33.0
Fix from $1,950 2021-03-18
Portainer HIGH 8.8
CVE-2020-24263

Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user …

Fix: after 1.24.1
Fix from $1,950 2021-03-16
Courier Authlib HIGH 7.5
CVE-2021-28374

The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissio…

Fix: 0.71.1-2+
Fix from $1,950 2021-03-15
Windows 10 HIGH 7.3
CVE-2021-27070

Windows 10 Update Assistant Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-03-11
Swagger Codegen MEDIUM 5.5
CVE-2021-21364

swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in differen…

Fix: 2.4.19+
Fix from $1,600 2021-03-11
Android HIGH 7.8
CVE-2021-0372

In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local…

Mitigation only
Fix from $1,950 2021-03-10
Chrome MEDIUM 6.5
CVE-2021-21177EPSS 17%

Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive informat…

Fix: 89.0.4389.72+
Fix from $1,600 2021-03-09
Ifix MEDIUM 5.5
CVE-2019-18243

HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry. This may al…

Fix: after 6.1
Fix from $1,600 2021-02-18
Ifix MEDIUM 5.5
CVE-2019-18255

HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may…

Fix: after 6.1
Fix from $1,600 2021-02-18
Compute Stick Stk1a32sc Firmware HIGH 7.8
CVE-2021-0109

Insecure inherited permissions for the Intel(R) SOC driver package for STK1A32SC before version 604 may allow an authenticated user to potentially en…

Fix: 604+
Fix from $1,950 2021-02-17
Android HIGH 7.8
CVE-2021-0336

In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local esca…

Patch available
Fix from $1,950 2021-02-10
Android HIGH 7.8
CVE-2021-0334

In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains…

Patch available
Fix from $1,950 2021-02-10
Total Protection HIGH 7.8
CVE-2021-23874 KEV

Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execu…

Fix: 16.0.30+
Fix from $1,950 2021-02-10
Emc Powerscale Onefs HIGH 7.8
CVE-2020-26194

Dell EMC PowerScale OneFS versions 8.1.2 and 8.2.2 contain an Incorrect Permission Assignment for a Critical Resource vulnerability. This may allow a…

Mitigation only
Fix from $1,950 2021-02-09
Emc Powerscale Onefs MEDIUM 5.5
CVE-2020-26196

Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue. A user with the BackupAdmin role may potentia…

Mitigation only
Fix from $1,600 2021-02-09
Psyprax MEDIUM 5.5
CVE-2020-10553

An issue was discovered in Psyprax before 3.2.2. The file %PROGRAMDATA%\Psyprax32\PPScreen.ini contains a hash for the lockscreen (aka screensaver) o…

Fix: 3.2.2+
Fix from $1,600 2021-02-05
Serv U HIGH 7.1
CVE-2021-25276

In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world r…

Fix: 15.2.2+
Fix from $1,950 2021-02-03
Smartagent HIGH 8.8
CVE-2021-3165

SmartAgent 3.1.0 allows a ViewOnly attacker to create a SuperUser account via the /#/CampaignManager/users URI.

No fix yet
Fix from $1,950 2021-01-26
Traffic Control MEDIUM 5.8
CVE-2020-17522

When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissi…

Fix: after 4.1.0
Fix from $1,600 2021-01-26
Fastify Csrf HIGH 8.8
CVE-2020-28482

This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts…

Fix: 3.0.0+
Fix from $1,950 2021-01-19
Oaklouds Portal CRITICAL 9.8
CVE-2021-22850

HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.

Mitigation only
Fix from $2,300 2021-01-19
Secure Firewall Management Center MEDIUM 5.5
CVE-2021-1126

A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to…

Fix: 6.7.0+
Fix from $1,600 2021-01-13
Security Guardium Data Encryption HIGH 8.1
CVE-2019-4702

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be r…

Patch available
Fix from $1,950 2021-01-13
Android MEDIUM 5.5
CVE-2021-0304

In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local informa…

Mitigation only
Fix from $1,600 2021-01-11
Vue Testing System HIGH 7.8
CVE-2020-36154

The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory,…

No fix yet
Fix from $1,950 2021-01-04
Teamwork Cloud HIGH 7.8
CVE-2020-25507

An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivileged attacker to execute arb…

Fix: after 19.0
Fix from $1,950 2020-12-28
Debian Linux HIGH 7.0
CVE-2020-28169

The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account…

Fix: 2020-12-18+
Fix from $1,950 2020-12-24
Dsl2888a Firmware MEDIUM 6.5
CVE-2020-24578

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a mali…

No fix yet
Fix from $1,600 2020-12-22
Odoo MEDIUM 6.5
CVE-2018-15645

Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users …

Fix: after 12.0
Fix from $1,600 2020-12-22