Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.8 CVE-2022-43517 A vulnerability has been identified in Simcenter STAR-CCM+ (All versions < V2306). The affected application improperly assigns file permissions to in… Star Ccm\+ Mitigation only Fix from $1,9502022-12-13 MEDIUM 6.5 CVE-2022-23143 ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions… Otcp Firmware 2.21.40.06+ Fix from $1,6002022-12-05 MEDIUM 6.5 CVE-2022-46338 g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writabl… Debian Linux Patch available Fix from $1,6002022-11-30 MEDIUM 5.5 CVE-2022-41926 Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the receiver is not protected by broa… Talk 14.1.0+ Fix from $1,6002022-11-25 HIGH 7.8 CVE-2022-44725 OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to cr… Local Discovery Server 1.04.405.479+ Fix from $1,9502022-11-17 HIGH 8.8 CVE-2022-45193 CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privilege escalation. Cbrn Analysis 22+ Fix from $1,9502022-11-12 MEDIUM 5.5 CVE-2022-44746 Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows)… Cyber Protect Home Office 40107+ Fix from $1,6002022-11-07 HIGH 7.8 CVE-2022-44732 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) befor… Cyber Protect Home Office 39900+ Fix from $1,9502022-11-07 HIGH 7.8 CVE-2022-44733 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) befor… Cyber Protect Home Office 39900+ Fix from $1,9502022-11-07 MEDIUM 5.5 CVE-2022-2188 Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak dir… Data Exchange Layer 6.0.0.280+ Fix from $1,6002022-11-07 HIGH 8.8 CVE-2022-3258 Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentication Abuse. Workforce Access 7.7.1+ Fix from $1,9502022-11-03 MEDIUM 5.5 CVE-2022-32929 A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 15.7 and iPadOS 15.7, iOS 16… Ipados 15.7+ Fix from $1,6002022-11-01 HIGH 7.8 CVE-2022-36122 The Automox Agent before 40 on Windows incorrectly sets permissions on key files. Automox 40+ Fix from $1,9502022-10-21 HIGH 7.3 CVE-2022-22248 An Incorrect Permission Assignment vulnerability in shell processing of Juniper Networks Junos OS Evolved allows a low-privileged local user to modif… Junos Os Evolved Mitigation only Fix from $1,9502022-10-18 MEDIUM 5.5 CVE-2022-26238 The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged u… Remisol Advance after 2.0.12.1 Fix from $1,6002022-10-06 MEDIUM 5.5 CVE-2022-26236 The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-pri… Remisol Advance after 2.0.12.1 Fix from $1,6002022-10-06 MEDIUM 6.7 CVE-2022-2975 A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative us… Aura Application Enablement Services 8.1.3.5 / 10.1.0.2+ Fix from $1,6002022-10-06 MEDIUM 5.5 CVE-2022-26239 The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows unprivileged use… Remisol Advance after 2.0.12.1 Fix from $1,6002022-10-06 MEDIUM 6.5 CVE-2022-26240 The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged us… Remisol Advance after 2.0.12.1 Fix from $1,6002022-10-06 MEDIUM 5.5 CVE-2022-26237 The default privileges for the running service Normand Viewer Service in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged us… Remisol Advance after 2.0.12.1 Fix from $1,6002022-10-06 HIGH 8.8 CVE-2022-40756 If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or… Psql 14.21.022 / 15.01.017+ Fix from $1,9502022-09-30 MEDIUM 5.3 CVE-2020-15328 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 MEDIUM 5.3 CVE-2020-15329 Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions. Cloudcnm Secumanager No fix yet Fix from $1,6002022-09-29 HIGH 8.8 CVE-2022-40298 Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the Ai… Airmedia Mitigation only Fix from $1,9502022-09-23 CRITICAL 9.9 CVE-2022-28802 Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScript code. In other words, Cod… Code By Zapier 2022-08-17+ Fix from $2,3002022-09-21 CRITICAL 9.8 CVE-2017-20148 In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck us… Logcheck after 1.3.23 Fix from $2,3002022-09-20 HIGH 7.1 CVE-2022-2995 Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modifica… Cri O Patch available Fix from $1,9502022-09-19 HIGH 7.8 CVE-2022-2332 A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to insecure permission assignment. Softmaster Mitigation only Fix from $1,9502022-09-16 MEDIUM 5.3 CVE-2022-22330 IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attack… Control Desk Mitigation only Fix from $1,6002022-09-13 HIGH 7.8 CVE-2022-20398 In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could le… Android Patch available Fix from $1,9502022-09-13