Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2022-20399
In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default value. This could lead to loc…
Android
Patch available
MEDIUM 5.4
CVE-2022-39207
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save build artifacts for later retriev…
Onedev
7.3.0+
HIGH 8.8
CVE-2022-36103
Talos Linux is a Linux distribution built for Kubernetes deployments. Talos worker nodes use a join token to get accepted into the Talos cluster. Due…
Talos Linux
1.2.2+
MEDIUM 6.7
CVE-2022-36670
PCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges t…
Endpoint
5.17.470+
MEDIUM 6.7
CVE-2022-37771
IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify pr…
Malware Fighter
No fix yet
HIGH 8.8
CVE-2022-37435
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This i…
Shenyu
Patch available
HIGH 7.5
CVE-2022-32777
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and…
Avideo
Mitigation only
HIGH 7.5
CVE-2022-32778
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and…
Avideo
Mitigation only
CRITICAL 9.8
CVE-2020-27836
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker…
Openshift Container Platform
Patch available
HIGH 8.8
CVE-2022-35167
Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.
Cloud Print Management
Mitigation only
MEDIUM 6.5
CVE-2022-22411
IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate c…
Spectrum Scale Data Access Services
Patch available
CRITICAL 9.8
CVE-2021-22648
Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.
Twinsoft
1.46 / 12.4+
MEDIUM 6.5
CVE-2022-34112
An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstall the plugin, a right normall…
Dataease
No fix yet
MEDIUM 6.5
CVE-2022-1655
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without …
Openstack
Mitigation only
HIGH 7.8
CVE-2022-34891
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker…
Parallels Desktop
No fix yet
HIGH 7.8
CVE-2021-45492
In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be the first entry in the system-w…
Sage 300
after 2022
HIGH 7.5
CVE-2022-20234
In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, it gets both 'mComponentName'…
Android
Patch available
HIGH 7.8
CVE-2022-20218
In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic error in the code. This could le…
Android
Mitigation only
HIGH 7.8
CVE-2022-33695
Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.
Android
Mitigation only
HIGH 8.8
CVE-2021-38289
An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate…
Novaicare
No fix yet
HIGH 8.8
CVE-2022-30929
Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.
Mini Tmall
No fix yet
MEDIUM 5.5
CVE-2014-0068
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.
Openshift Origin Node Util
Mitigation only
MEDIUM 5.5
CVE-2022-23725
PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circu…
Pingid Integration For Windows Login
2.8+
HIGH 7.3
CVE-2022-34043
Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perform a DLL hijacking attack an…
Nomachine
No fix yet
MEDIUM 5.3
CVE-2021-38879
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se…
Jazz Team Server
Patch available
MEDIUM 5.3
CVE-2021-20355
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to se…
Jazz Team Server
Patch available
MEDIUM 6.5
CVE-2022-34012
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privilege…
Oneblog
No fix yet
MEDIUM 6.5
CVE-2022-1596
Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to …
Rex640 Pcl1 Firmware
1.1.4 / 1.2.1+
HIGH 7.8
CVE-2022-31464
Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing the service binary path.
Protect
No fix yet
HIGH 7.5
CVE-2022-32155
In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential expos…
Splunk
8.2.2106 / 9.0+