Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Wing Ftp Server HIGH 7.8
CVE-2020-9470

An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may vi…

Fix: after 6.2.5
Fix from $1,950 2020-03-07
Wing Ftp Server HIGH 7.8
CVE-2020-8635

Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local…

No fix yet
Fix from $1,950 2020-03-07
Platform Lsf HIGH 7.8
CVE-2020-4278

IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges…

Patch available
Fix from $1,950 2020-03-05
Ilc 2050 Bi Firmware CRITICAL 9.4
CVE-2020-8768

An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. There is an insecure mechanis…

Fix: 1.2.3+
Fix from $2,300 2020-02-17
Openshift Service Mesh HIGH 7.8
CVE-2020-1704

An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the opens…

Fix: 1.0.8+
Fix from $1,950 2020-02-17
Vantage Velocity Firmware CRITICAL 9.8
CVE-2020-9024

Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and…

No fix yet
Fix from $2,300 2020-02-17
Codoforum MEDIUM 5.4
CVE-2020-7050

Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatic…

Fix: after 4.8.4
Fix from $1,600 2020-02-15
Itop HIGH 8.1
CVE-2019-11215

In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.data…

Fix: after 2.6.0
Fix from $1,950 2020-02-14
Manycore Platform Software Stack HIGH 7.8
CVE-2020-0563

Improper permissions in the installer for Intel(R) MPSS before version 3.8.6 may allow an authenticated user to potentially enable escalation of priv…

Fix: 3.8.6+
Fix from $1,950 2020-02-13
Codoforum MEDIUM 6.1
CVE-2020-7051

Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lac…

Fix: after 4.8.4
Fix from $1,600 2020-02-13
Windows 10 HIGH 7.8
CVE-2020-0668EPSS 26%

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privile…

Patch available
Fix from $1,950 2020-02-11
Mi Browser HIGH 8.0
CVE-2019-13321

This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User inte…

Fix: 10.4.0+
Fix from $1,950 2020-02-10
Joomla\! MEDIUM 5.3
CVE-2011-4912

Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.

Fix: after 1.5.13
Fix from $1,600 2020-02-04
Anti Threat Toolkit HIGH 7.8
CVE-2019-20358

Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the…

Fix: after 1.62.0.1218
Fix from $1,950 2020-01-30
Streaming Engine HIGH 7.8
CVE-2019-7656

A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges to root. T…

Fix: after 4.8.0
Fix from $1,950 2020-01-29
Generic Pcl5 Driver HIGH 7.8
CVE-2019-19363

An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation.…

Fix: 4.26+
Fix from $1,950 2020-01-24
Easyinstall MEDIUM 5.5
CVE-2019-19894

In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. An authenticated attacker (non…

No fix yet
Fix from $1,600 2020-01-23
Easyinstall HIGH 7.8
CVE-2019-19895

In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker c…

No fix yet
Fix from $1,950 2020-01-23
Ispconfig CRITICAL 9.8
CVE-2012-2087

ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.

No fix yet
Fix from $2,300 2020-01-23
Data Analytics Acceleration Library MEDIUM 5.5
CVE-2019-14629

Improper permissions in Intel(R) DAAL before version 2020 Gold may allow an authenticated user to potentially enable information disclosure via local…

Fix: 2020+
Fix from $1,600 2020-01-17
Openstack Cloud HIGH 8.8
CVE-2019-3683

The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/k…

Fix: 2019-02-18+
Fix from $1,950 2020-01-17
Centreon HIGH 7.8
CVE-2019-20327

Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrappe…

Fix: after 19.10
Fix from $1,950 2020-01-16
Pyinstaller HIGH 7.8
CVE-2019-16784

In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software usin…

Fix: 3.6+
Fix from $1,950 2020-01-14
Slurm MEDIUM 5.5
CVE-2019-19727

SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.

Fix: 18.08.9 / 19.05.5+
Fix from $1,600 2020-01-13
Yetishare MEDIUM 6.1
CVE-2019-19736

MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potent…

Fix: after 4.5.3
Fix from $1,600 2019-12-30
Debian Lan Config HIGH 7.8
CVE-2019-3467

Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive A…

Fix: 0.26 / 2.11.10+
Fix from $1,950 2019-12-23
301 Redirects CRITICAL 9.0
CVE-2019-19915

The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or i…

Fix: 2.45+
Fix from $2,300 2019-12-19
Ansible Tower MEDIUM 5.5
CVE-2019-19341

A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both …

Fix: 3.6.2+
Fix from $1,600 2019-12-19
Coldfusion CRITICAL 9.8
CVE-2019-8256

ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitat…

Mitigation only
Fix from $2,300 2019-12-19
Shadow HIGH 7.8
CVE-2019-19882

shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid p…

Patch available
Fix from $1,950 2019-12-18