Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.8 CVE-2022-43773EPSS 22% Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed with a sample HSQLDB data sourc… Vantara Pentaho Business Analytics Server 9.3.0.2+ Fix from $1,9502023-04-03 HIGH 7.8 CVE-2023-1516 RoboDK versions 5.5.3 and prior contain an insecure permission assignment to critical directories vulnerability, which could allow a local user to … Robodk after 5.5.3 Fix from $1,9502023-03-28 HIGH 8.1 CVE-2023-25817 Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions … Nextcloud Server 24.0.9+ Fix from $1,9502023-03-27 HIGH 7.8 CVE-2023-1135 In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in l… Infrasuite Device Master 1.0.5+ Fix from $1,9502023-03-27 MEDIUM 6.5 CVE-2023-27096 Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information via the ConfigVerifyController … Hippo4j No fix yet Fix from $1,6002023-03-27 MEDIUM 5.5 CVE-2022-3146 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T… Openstack Mitigation only Fix from $1,6002023-03-23 MEDIUM 5.5 CVE-2022-3101 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T… Openstack Mitigation only Fix from $1,6002023-03-23 MEDIUM 5.3 CVE-2023-27084 Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information via the AttachmentController… Dreamer Cms No fix yet Fix from $1,6002023-03-16 MEDIUM 6.5 CVE-2023-27095 Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserControl… Hippo4j 1.4.3+ Fix from $1,6002023-03-16 HIGH 7.0 CVE-2023-23939 Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creat… Azure Setup Kubectl 3.0+ Fix from $1,9502023-03-06 CRITICAL 9.8 CVE-2023-24205 Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration… Clash No fix yet Fix from $2,3002023-02-23 HIGH 8.1 CVE-2021-3172 An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature. Php Fusion 9.10.00+ Fix from $1,9502023-02-17 HIGH 7.8 CVE-2022-25992 Insecure inherited permissions in the Intel(R) oneAPI Toolkits oneapi-cli before version 0.2.0 may allow an authenticated user to potentially enable … Oneapi Cli 0.2.0+ Fix from $1,9502023-02-16 MEDIUM 6.1 CVE-2022-21939 Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 … Metasys System Configuration Tool 14.2.3 / 15.0.3+ Fix from $1,6002023-02-09 MEDIUM 5.7 CVE-2023-25150 Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to … Richdocuments 3.8.7 / 4.2.9+ Fix from $1,6002023-02-08 HIGH 7.5 CVE-2021-37304 An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information … Jeecg after 2.4.5 Fix from $1,9502023-02-03 HIGH 7.5 CVE-2021-37305 An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via … Jeecg after 2.4.5 Fix from $1,9502023-02-03 HIGH 7.5 CVE-2021-37306 An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via … Jeecg after 2.4.5 Fix from $1,9502023-02-03 HIGH 7.8 CVE-2022-42972 A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege escalation when a local attack… Apc Easy Ups Online Monitoring Software 2.5-ga / 2.5-gs+ Fix from $1,9502023-02-01 HIGH 8.8 CVE-2022-44715 Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload. Ngeniusone Mitigation only Fix from $1,9502023-01-27 HIGH 7.8 CVE-2022-44263 Dentsply Sirona Sidexis <= 4.3 is vulnerable to Incorrect Access Control. Sidexis after 4.3 Fix from $1,9502023-01-26 MEDIUM 6.5 CVE-2023-23610 GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any use… Glpi 9.5.12 / 10.0.6+ Fix from $1,6002023-01-26 MEDIUM 5.5 CVE-2023-20923 In exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to a permissions bypass. This c… Android Mitigation only Fix from $1,6002023-01-26 HIGH 7.8 CVE-2023-22592 IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.4 could allow a local user to perform unauthorized actions due to insufficient permi… Robotic Process Automation For Cloud Pak 21.0.5+ Fix from $1,9502023-01-18 HIGH 7.8 CVE-2022-34457 Dell command configuration, version 4.8 and prior, contains improper folder permission when installed not to default path but to non-secured path whi… Command\|configure 4.9.0+ Fix from $1,9502023-01-18 MEDIUM 5.3 CVE-2022-48257 In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp. Eternal Terminal Patch available Fix from $1,6002023-01-13 MEDIUM 5.5 CVE-2022-39186 EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions Bv 10 Firmware Mitigation only Fix from $1,6002023-01-12 MEDIUM 5.5 CVE-2022-47927 An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existin… Fedora 1.35.9 / 1.38.5+ Fix from $1,6002023-01-12 MEDIUM 5.3 CVE-2022-4630 Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master. Daloradius Patch available Fix from $1,6002022-12-21 HIGH 7.5 CVE-2022-42949 Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions. Subsites after 2.6.0 Fix from $1,9502022-12-21