Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.9
CVE-2022-26247
TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability allows attackers to modify t…
Teamwork Management System
No fix yet
HIGH 7.8
CVE-2022-26526
Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDA…
Anaconda3
after 2021.11.0.0
MEDIUM 5.3
CVE-2022-21946
A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local us…
Cscreen
after 1.3
HIGH 7.6
CVE-2022-21819
NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physic…
Jetson Linux
32.7.1+
HIGH 7.8
CVE-2022-22141
'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL configurat…
Centum Cs 3000 Firmware
Mitigation only
HIGH 7.8
CVE-2022-22148
'Root Service' service implemented in the following Yokogawa Electric products creates some named pipe with improper ACL configuration. CENTUM CS 300…
Centum Cs 3000 Firmware
Mitigation only
HIGH 7.8
CVE-2021-42855
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that c…
Steelcentral Appinternals Dynamic Sampling Agent
11.8.8 / 12.13.0+
HIGH 7.8
CVE-2021-4199
Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Securit…
Antivirus Plus
7.4.3.146 / 26.0.3.29+
MEDIUM 6.3
CVE-2021-3631
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access fil…
Libvirt
7.5.0+
CRITICAL 9.1
CVE-2022-25010
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
Stepmania
after 5.0.12
HIGH 7.5
CVE-2022-24327
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
Hub
2021.1.13890+
MEDIUM 5.5
CVE-2022-0247
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO…
Fuchsia
2022-01-03+
MEDIUM 6.5
CVE-2021-3557
A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-serve…
Openshift Gitops
1.1.1+
HIGH 7.8
CVE-2022-0483
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53
Vss Doctor
Mitigation only
CRITICAL 9.1
CVE-2021-44521EPSS 55%
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enab…
Cassandra
3.0.26 / 3.11.12+
HIGH 7.8
CVE-2021-39992
There is an improper security permission configuration vulnerability on ACPU.Successful exploitation of this vulnerability may affect service confide…
Emui
No fix yet
HIGH 8.8
CVE-2021-22284
Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to execute arbitrary code in the nod…
Opc Server For Ac 800m
6.0.0-4+
CRITICAL 9.8
CVE-2021-29396
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various function…
Northstar Club Management
Mitigation only
MEDIUM 6.5
CVE-2022-0277
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11.
Microweber
after 1.2.10
MEDIUM 5.3
CVE-2022-21694
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The…
Onionshare
2.5+
CRITICAL 9.8
CVE-2021-22566
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged …
Fuchsia
Patch available
HIGH 7.8
CVE-2021-39621
In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could le…
Android
Mitigation only
HIGH 7.8
CVE-2021-39627
In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could le…
Android
Mitigation only
CRITICAL 9.1
CVE-2022-22988
File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for …
Edgerover
1.5.0-576+
HIGH 7.3
CVE-2022-23132
During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix …
Fedora
after 5.4.8
HIGH 7.8
CVE-2021-20172
All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of…
Genie Installer
No fix yet
HIGH 7.3
CVE-2021-44466
Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-defau…
Bitmask Riseup Vpn
Patch available
HIGH 7.5
CVE-2021-20874
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 …
Groupsession
after 5.1.1
HIGH 7.8
CVE-2021-27445
Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges on the device.
Amegaview
after 3.0
MEDIUM 6.7
CVE-2021-0904
In SRAMROM, there is a possible permission bypass due to an insecure permission setting. This could lead to local escalation of privilege with System…
Android
Mitigation only