Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.8 CVE-2022-31465 A vulnerability has been identified in Xpedition Designer VX.2.10 (All versions < VX.2.10 Update 13), Xpedition Designer VX.2.11 (All versions < VX.2… Xpedition Designer Mitigation only Fix from $1,9502022-06-14 MEDIUM 6.5 CVE-2021-40649 In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set. Connx No fix yet Fix from $1,6002022-06-14 CRITICAL 9.8 CVE-2022-33175 Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field t… Basic Pdu Firmware 3.30.30+ Fix from $2,3002022-06-13 HIGH 7.5 CVE-2022-1412 The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filenames, allowing any unauthenti… Log Wp Mail after 0.1 Fix from $1,9502022-06-13 HIGH 7.5 CVE-2022-25151 Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failu… On Premise 6.35.37347.20040+ Fix from $1,9502022-06-09 HIGH 7.8 CVE-2022-30700 An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with es… Apex One 14.0.10349+ Fix from $1,9502022-05-27 MEDIUM 6.5 CVE-2022-1348 A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances … Fedora 3.20.0+ Fix from $1,6002022-05-25 HIGH 7.5 CVE-2022-30990 Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before bui… Cyber Protect 15+ Fix from $1,9502022-05-18 MEDIUM 6.1 CVE-2022-25172 An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session c… Ir302 Firmware after 3.5.4 Fix from $1,6002022-05-12 HIGH 7.8 CVE-2022-23743 Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permiss… Zonealarm 15.8.211.192119+ Fix from $1,9502022-05-11 HIGH 7.5 CVE-2021-44167 An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6… Forticlient after 7.0.2 Fix from $1,9502022-05-11 MEDIUM 6.5 CVE-2021-27764 Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI) Bigfix Webui Mitigation only Fix from $1,6002022-05-06 HIGH 7.8 CVE-2022-29263 On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13… Access Policy Manager Clients Mitigation only Fix from $1,9502022-05-05 HIGH 7.3 CVE-2022-22521 In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users priv… Benchmark Programming Tool 1.2.72+ Fix from $1,9502022-04-27 MEDIUM 6.5 CVE-2021-23055 On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not appl… Nginx Ingress Controller 1.12.3 / 2.0.3+ Fix from $1,6002022-04-21 HIGH 8.1 CVE-2022-24872 Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable with… Shopware 6.4.10.1+ Fix from $1,9502022-04-20 MEDIUM 5.7 CVE-2021-38483 The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileges access to overwrite the bi… Roboguide after 9.40083.00.05 Fix from $1,6002022-04-20 HIGH 7.0 CVE-2022-29527 Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate p… Amazon Ssm Agent 3.1.1208.0+ Fix from $1,9502022-04-20 HIGH 7.8 CVE-2022-22960 KEVEPSS 36% VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in sup… Cloud Foundation 5.0 / 9.0+ Fix from $1,9502022-04-13 HIGH 7.8 CVE-2022-23448 A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 U… Simatic Energy Manager Basic 7.3+ Fix from $1,9502022-04-12 HIGH 7.8 CVE-2022-1316 Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation Zerotierone 1.8.8+ Fix from $1,9502022-04-11 HIGH 7.8 CVE-2022-0556 A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1… Zyxel Ap Configurator Mitigation only Fix from $1,9502022-04-11 MEDIUM 6.7 CVE-2021-36290 Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vuln… Emc Unity Operating Environment after 8.1.21.266 Fix from $1,6002022-04-08 HIGH 7.8 CVE-2022-22516 The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory spac… Control Rte Sl 3.5.18.0+ Fix from $1,9502022-04-07 HIGH 7.8 CVE-2022-26250 Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges. Synaman after 5.1 Fix from $1,9502022-04-06 HIGH 7.5 CVE-2022-26281 BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue. Bigant Server No fix yet Fix from $1,9502022-04-05 MEDIUM 6.5 CVE-2022-23869 In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be res… Ruoyi No fix yet Fix from $1,6002022-03-30 HIGH 8.8 CVE-2022-22941 An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if… Salt 3002.8 / 3003.4+ Fix from $1,9502022-03-29 MEDIUM 5.9 CVE-2022-24769 Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to… Fedora 1.1.2 / 20.10.14+ Fix from $1,6002022-03-24 HIGH 7.8 CVE-2022-0652 Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to… Unified Threat Management 9.710+ Fix from $1,9502022-03-22