Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
MEDIUM 5.5 CVE-2022-20399 In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default value. This could lead to loc… Android Patch available Fix from $1,6002022-09-13 MEDIUM 5.4 CVE-2022-39207 Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retriev… Onedev 7.3.0+ Fix from $1,6002022-09-13 HIGH 8.8 CVE-2022-36103 Talos Linux is a Linux distribution built for Kubernetes deployments. Talos worker nodes use a join token to get accepted into the Talos cluster. Due… Talos Linux 1.2.2+ Fix from $1,9502022-09-13 MEDIUM 6.7 CVE-2022-36670 PCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges t… Endpoint 5.17.470+ Fix from $1,6002022-09-06 MEDIUM 6.7 CVE-2022-37771 IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify pr… Malware Fighter No fix yet Fix from $1,6002022-09-06 HIGH 8.8 CVE-2022-37435 Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This i… Shenyu Patch available Fix from $1,9502022-09-01 HIGH 7.5 CVE-2022-32777 An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and… Avideo Mitigation only Fix from $1,9502022-08-22 HIGH 7.5 CVE-2022-32778 An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and… Avideo Mitigation only Fix from $1,9502022-08-22 CRITICAL 9.8 CVE-2020-27836 A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker… Openshift Container Platform Patch available Fix from $2,3002022-08-22 HIGH 8.8 CVE-2022-35167 Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions. Cloud Print Management Mitigation only Fix from $1,9502022-08-19 MEDIUM 6.5 CVE-2022-22411 IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate c… Spectrum Scale Data Access Services Patch available Fix from $1,6002022-08-10 CRITICAL 9.8 CVE-2021-22648 Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file. Twinsoft 1.46 / 12.4+ Fix from $2,3002022-07-28 MEDIUM 6.5 CVE-2022-34112 An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normall… Dataease No fix yet Fix from $1,6002022-07-22 MEDIUM 6.5 CVE-2022-1655 An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without … Openstack Mitigation only Fix from $1,6002022-07-22 HIGH 7.8 CVE-2022-34891 This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker… Parallels Desktop No fix yet Fix from $1,9502022-07-18 HIGH 7.8 CVE-2021-45492 In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-w… Sage 300 after 2022 Fix from $1,9502022-07-14 HIGH 7.5 CVE-2022-20234 In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, it gets both 'mComponentName'… Android Patch available Fix from $1,9502022-07-13 HIGH 7.8 CVE-2022-20218 In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic error in the code. This could le… Android Mitigation only Fix from $1,9502022-07-13 HIGH 7.8 CVE-2022-33695 Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service. Android Mitigation only Fix from $1,9502022-07-12 HIGH 8.8 CVE-2021-38289 An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate… Novaicare No fix yet Fix from $1,9502022-07-12 HIGH 8.8 CVE-2022-30929 Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper. Mini Tmall No fix yet Fix from $1,9502022-07-06 MEDIUM 5.5 CVE-2014-0068 It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission. Openshift Origin Node Util Mitigation only Fix from $1,6002022-06-30 MEDIUM 5.5 CVE-2022-23725 PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circu… Pingid Integration For Windows Login 2.8+ Fix from $1,6002022-06-30 HIGH 7.3 CVE-2022-34043 Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perform a DLL hijacking attack an… Nomachine No fix yet Fix from $1,9502022-06-29 MEDIUM 5.3 CVE-2021-38879 IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se… Jazz Team Server Patch available Fix from $1,6002022-06-24 MEDIUM 5.3 CVE-2021-20355 IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se… Jazz Team Server Patch available Fix from $1,6002022-06-24 MEDIUM 6.5 CVE-2022-34012 Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privilege… Oneblog No fix yet Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-1596 Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to … Rex640 Pcl1 Firmware 1.1.4 / 1.2.1+ Fix from $1,6002022-06-21 HIGH 7.8 CVE-2022-31464 Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing the service binary path. Protect No fix yet Fix from $1,9502022-06-16 HIGH 7.5 CVE-2022-32155 In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential expos… Splunk 8.2.2106 / 9.0+ Fix from $1,9502022-06-15