Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Kps2204 6 Port Managed Din Rail Programmable Serial Device Firmware CRITICAL 9.8
CVE-2020-25011

A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.…

Mitigation only
Fix from $2,300 2020-12-17
Netcrunch CRITICAL 9.8
CVE-2019-14480

AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or…

Fix: after 11.0.0.5282
Fix from $2,300 2020-12-16
Compactrio Firmware HIGH 7.5
CVE-2020-25191

Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a function that c…

Fix: 20.5+
Fix from $1,950 2020-12-11
Virusscan Enterprise MEDIUM 6.7
CVE-2020-7337

Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administr…

Fix: 8.8+
Fix from $1,600 2020-12-09
Cloud Pak For Security MEDIUM 5.3
CVE-2020-4625

IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly fla…

Patch available
Fix from $1,600 2020-11-30
Fedora HIGH 8.8
CVE-2020-29074

scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.

Patch available
Fix from $1,950 2020-11-25
Gluster Block MEDIUM 5.5
CVE-2020-10762

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes …

Fix: 0.5.1+
Fix from $1,600 2020-11-24
Ovoicemanager CRITICAL 9.8
CVE-2020-11831

OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1.

Mitigation only
Fix from $2,300 2020-11-19
Kata Containers HIGH 7.1
CVE-2020-28914

An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a fil…

Fix: 1.11.5+
Fix from $1,950 2020-11-17
Nuc 8 Mainstream G Kit Nuc8i5inh Firmware HIGH 7.8
CVE-2020-24525

Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of pri…

Mitigation only
Fix from $1,950 2020-11-12
Media Sdk HIGH 7.8
CVE-2019-11121

Improper file permissions in the installer for the Intel(R) Media SDK for Windows before version 2019 R1 may allow an authenticated user to potential…

Patch available
Fix from $1,950 2020-11-12
Azure Sphere MEDIUM 6.2
CVE-2020-16990

Azure Sphere Information Disclosure Vulnerability

Fix: 20.07+
Fix from $1,600 2020-11-11
Bluestacks HIGH 7.8
CVE-2020-24367

Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later e…

Fix: after 4.230
Fix from $1,950 2020-11-10
32s330 Firmware HIGH 7.8
CVE-2020-28055

A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporatio…

No fix yet
Fix from $1,950 2020-11-10
Sd Wan HIGH 7.8
CVE-2020-3595

A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating…

Fix: 20.1.2 / 20.3.2+
Fix from $1,950 2020-11-06
Debian Linux MEDIUM 5.5
CVE-2020-17490

The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.

Fix: 2015.8.10 / 2015.8.13+
Fix from $1,600 2020-11-06
Ubuntu Linux HIGH 7.8
CVE-2020-15708

Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite ar…

Mitigation only
Fix from $1,950 2020-11-06
Dr.fone HIGH 7.8
CVE-2020-27992

Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Wondershare\dr.fone\Library\Driv…

No fix yet
Fix from $1,950 2020-11-02
Router Manager MEDIUM 6.1
CVE-2020-27658

Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easi…

Fix: 1.2.4-8081+
Fix from $1,600 2020-10-29
Open Tftp Server HIGH 7.8
CVE-2020-26130

Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient access restrictions in the d…

No fix yet
Fix from $1,950 2020-10-28
Open Dhcp Server HIGH 7.8
CVE-2020-26131

Issues were discovered in Open DHCP Server (Regular) 1.75 and Open DHCP Server (LDAP Based) 0.1Beta. Due to insufficient access restrictions in the d…

No fix yet
Fix from $1,950 2020-10-28
Home Dns Server HIGH 7.8
CVE-2020-26132

An issue was discovered in Home DNS Server 0.10. Due to insufficient access restrictions in the default installation directory, an attacker can eleva…

Mitigation only
Fix from $1,950 2020-10-28
Dual Dhcp Dns Server HIGH 7.8
CVE-2020-26133

An issue was discovered in Dual DHCP DNS Server 7.40. Due to insufficient access restrictions in the default installation directory, an attacker can …

Mitigation only
Fix from $1,950 2020-10-28
True Image HIGH 7.3
CVE-2020-10140

Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C…

Mitigation only
Fix from $1,950 2020-10-21
Android MEDIUM 5.5
CVE-2020-0410

In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclo…

Patch available
Fix from $1,600 2020-10-14
Foxit Reader HIGH 7.8
CVE-2020-17414

This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798. An attacker must first obtai…

Fix: after 10.0.1.35811
Fix from $1,950 2020-10-13
Foxit Reader HIGH 7.8
CVE-2020-17415

This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PhantomPDF 10.0.0.35798. An attacker must first o…

Fix: after 10.0.1.35811
Fix from $1,950 2020-10-13
Debian Linux MEDIUM 5.5
CVE-2020-15250

In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like syste…

Fix: 3.1.1 / 4.13.1+
Fix from $1,600 2020-10-12
Automate HIGH 8.8
CVE-2020-15838

The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.

Fix: 2020.8+
Fix from $1,950 2020-10-09
Victor Web Client HIGH 8.1
CVE-2020-9048

A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated…

Fix: after 5.4.1
Fix from $1,950 2020-10-08