Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2022-31465
A vulnerability has been identified in Xpedition Designer VX.2.10 (All versions < VX.2.10 Update 13), Xpedition Designer VX.2.11 (All versions < VX.2…
Xpedition Designer
Mitigation only
MEDIUM 6.5
CVE-2021-40649
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
Connx
No fix yet
CRITICAL 9.8
CVE-2022-33175
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field t…
Basic Pdu Firmware
3.30.30+
HIGH 7.5
CVE-2022-1412
The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filenames, allowing any unauthenti…
Log Wp Mail
after 0.1
HIGH 7.5
CVE-2022-25151
Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failu…
On Premise
6.35.37347.20040+
HIGH 7.8
CVE-2022-30700
An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with es…
Apex One
14.0.10349+
MEDIUM 6.5
CVE-2022-1348
A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel executions of multiple instances …
Fedora
3.20.0+
HIGH 7.5
CVE-2022-30990
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before bui…
Cyber Protect
15+
MEDIUM 6.1
CVE-2022-25172
An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session c…
Ir302 Firmware
after 3.5.4
HIGH 7.8
CVE-2022-23743
Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permiss…
Zonealarm
15.8.211.192119+
HIGH 7.5
CVE-2021-44167
An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6…
Forticlient
after 7.0.2
MEDIUM 6.5
CVE-2021-27764
Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI)
Bigfix Webui
Mitigation only
HIGH 7.8
CVE-2022-29263
On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…
Access Policy Manager Clients
Mitigation only
HIGH 7.3
CVE-2022-22521
In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users priv…
Benchmark Programming Tool
1.2.72+
MEDIUM 6.5
CVE-2021-23055
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not appl…
Nginx Ingress Controller
1.12.3 / 2.0.3+
HIGH 8.1
CVE-2022-24872
Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable with…
Shopware
6.4.10.1+
MEDIUM 5.7
CVE-2021-38483
The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileges access to overwrite the bi…
Roboguide
after 9.40083.00.05
HIGH 7.0
CVE-2022-29527
Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate p…
Amazon Ssm Agent
3.1.1208.0+
HIGH 7.8
CVE-2022-22960 KEVEPSS 36%
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in sup…
Cloud Foundation
5.0 / 9.0+
HIGH 7.8
CVE-2022-23448
A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 U…
Simatic Energy Manager Basic
7.3+
HIGH 7.8
CVE-2022-1316
Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation
Zerotierone
1.8.8+
HIGH 7.8
CVE-2022-0556
A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1…
Zyxel Ap Configurator
Mitigation only
MEDIUM 6.7
CVE-2021-36290
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vuln…
Emc Unity Operating Environment
after 8.1.21.266
HIGH 7.8
CVE-2022-22516
The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory spac…
Control Rte Sl
3.5.18.0+
HIGH 7.8
CVE-2022-26250
Synaman v5.1 and below was discovered to contain weak file permissions which allows authenticated attackers to escalate privileges.
Synaman
after 5.1
HIGH 7.5
CVE-2022-26281
BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
Bigant Server
No fix yet
MEDIUM 6.5
CVE-2022-23869
In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be res…
Ruoyi
No fix yet
HIGH 8.8
CVE-2022-22941
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if…
Salt
3002.8 / 3003.4+
MEDIUM 5.9
CVE-2022-24769
Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to…
Fedora
1.1.2 / 20.10.14+
HIGH 7.8
CVE-2022-0652
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to…
Unified Threat Management
9.710+