Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Driver \& Support Assistant HIGH 7.8
CVE-2020-12302

Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user to potentially enable escala…

Fix: 20.7.26.7+
Fix from $1,950 2020-10-05
Cpanel HIGH 7.5
CVE-2020-26106

cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).

Fix: 88.0.3+
Fix from $1,950 2020-09-25
Hotspot Shield HIGH 7.8
CVE-2020-17365

Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially e…

Fix: after 10.3.0
Fix from $1,950 2020-09-24
Ios Xe MEDIUM 6.0
CVE-2020-3503

A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access …

Mitigation only
Fix from $1,600 2020-09-24
Ismartgate Pro Firmware CRITICAL 9.8
CVE-2020-12842

ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php.

No fix yet
Fix from $2,300 2020-09-24
Ismartgate Pro Firmware CRITICAL 9.8
CVE-2020-12838

ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.

No fix yet
Fix from $2,300 2020-09-24
Ismartgate Pro Firmware CRITICAL 9.8
CVE-2020-12839

ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php.

No fix yet
Fix from $2,300 2020-09-24
Pingid Integration For Windows Login HIGH 7.8
CVE-2020-25826

PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe.

Fix: 2.4.2+
Fix from $1,950 2020-09-23
Webaccess HIGH 7.8
CVE-2020-16202

WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution wi…

Fix: 9.0.1+
Fix from $1,950 2020-09-22
Operation Bridge Reporter HIGH 7.8
CVE-2020-11855

An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow lo…

Fix: after 10.40
Fix from $1,950 2020-09-22
Enterprise HIGH 8.8
CVE-2020-15776

An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as Http…

Fix: after 2020.2.4
Fix from $1,950 2020-09-18
Dbi MEDIUM 6.1
CVE-2014-10402

An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed …

Fix: after 1.643
Fix from $1,600 2020-09-16
Linux Kernel MEDIUM 5.5
CVE-2020-10781

A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/cla…

Fix: 5.8.0+
Fix from $1,600 2020-09-16
Dbi MEDIUM 6.1
CVE-2014-10401

An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed v…

Fix: 1.632+
Fix from $1,600 2020-09-11
Mcafee Agent HIGH 7.8
CVE-2020-7314

Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac prior t…

Fix: 5.6.6+
Fix from $1,950 2020-09-10
Barracudadrive HIGH 7.8
CVE-2020-23834

Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by r…

No fix yet
Fix from $1,950 2020-09-04
Emc Isilon Onefs HIGH 8.8
CVE-2020-5369

Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability. An authent…

Mitigation only
Fix from $1,950 2020-09-02
Vmg5313 B30b Firmware CRITICAL 9.8
CVE-2020-24355

Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows …

Fix: after 5.13
Fix from $2,300 2020-09-02
Parallels Desktop MEDIUM 6.5
CVE-2020-17402

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4 (47270). An attacke…

Fix: 16.0.0+
Fix from $1,600 2020-08-25
Capi Release HIGH 8.8
CVE-2020-5417

Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is tr…

Fix: 1.97.0 / 13.12.0+
Fix from $1,950 2020-08-21
Linux Kernel HIGH 7.1
CVE-2020-24394

In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks…

Fix: 5.7.8+
Fix from $1,950 2020-08-19
Encryption HIGH 7.8
CVE-2020-5385

Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of…

Fix: 2.8 / 10.8+
Fix from $1,950 2020-08-18
Ac 3165 Firmware HIGH 7.8
CVE-2020-0559

Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticat…

Fix: 21.40.5.1+
Fix from $1,950 2020-08-13
Server Board S2600wt Firmware HIGH 8.8
CVE-2020-8731

Incorrect execution-assigned permissions in the file system for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 m…

Fix: 1.59+
Fix from $1,950 2020-08-13
Adaptive Server Enterprise HIGH 7.8
CVE-2020-6295

Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential informat…

Mitigation only
Fix from $1,950 2020-08-12
Spectrum Protect Plus MEDIUM 5.5
CVE-2020-4631

IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full cont…

Fix: after 10.1.6
Fix from $1,600 2020-08-04
Streaming Engine HIGH 7.8
CVE-2019-19455

Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamin…

Fix: 4.8.5+
Fix from $1,950 2020-08-03
Unleashed Firmware HIGH 7.5
CVE-2020-13915

Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via a…

Fix: after 200.7.10.102.92
Fix from $1,950 2020-07-28
Trust Store \(ubuntu\) MEDIUM 5.0
CVE-2014-1422

In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the applic…

Fix: 1.1.0+
Fix from $1,600 2020-07-22
Creative Cloud Desktop Application CRITICAL 9.8
CVE-2020-9671

Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead…

Fix: after 5.1
Fix from $2,300 2020-07-17