Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.8 CVE-2021-42309 Microsoft SharePoint Server Remote Code Execution Vulnerability Sharepoint Enterprise Server Patch available Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-43065 A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows a… Fortinac 8.8.10 / 9.1.4+ Fix from $1,9502021-12-09 HIGH 7.1 CVE-2021-36133 The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the No… Op Tee Mitigation only Fix from $1,9502021-12-07 HIGH 7.0 CVE-2021-44512 World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of sessi… Tmate Ssh Server after 2.3.0 Fix from $1,9502021-12-07 HIGH 7.8 CVE-2021-43034 An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to execute arbitrary code as th… Unitrends Backup 10.5.5+ Fix from $1,9502021-12-06 HIGH 8.8 CVE-2021-43359 Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a … Ehrd Mitigation only Fix from $1,9502021-12-01 HIGH 7.2 CVE-2021-40101 An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password. Concrete Cms 8.5.7+ Fix from $1,9502021-11-30 MEDIUM 6.5 CVE-2021-44230 PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privi… Burp Suite after 2021.11 Fix from $1,6002021-11-30 MEDIUM 6.5 CVE-2021-43998 HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multipl… Vault after 1.7.5 Fix from $1,6002021-11-30 CRITICAL 9.1 CVE-2021-42115 Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated re… Topease after 7.1.27 Fix from $2,3002021-11-30 MEDIUM 5.7 CVE-2021-24703 The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any aut… Download Plugin 1.6.1+ Fix from $1,6002021-11-23 HIGH 7.8 CVE-2021-43019 Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe servi… Creative Cloud Desktop Application after 5.5 Fix from $1,9502021-11-23 MEDIUM 6.5 CVE-2021-39235 In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated users with valid READ block to… Ozone 1.2.0+ Fix from $1,6002021-11-19 HIGH 7.8 CVE-2021-0064 Insecure inherited permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated… Ax210 Firmware 22.40+ Fix from $1,9502021-11-17 HIGH 7.8 CVE-2021-33091 Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit audio driver pack before version 1.3 may allow an authenticated u… Nuc M15 Laptop Kit Audio Driver Pack 1.3+ Fix from $1,9502021-11-17 HIGH 7.8 CVE-2021-33093 Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Serial IO driver pack before version 30.100.2104.1 may allow an a… Nuc M15 Laptop Kit Serial Io Driver Pack 30.100.2104.1+ Fix from $1,9502021-11-17 HIGH 7.8 CVE-2021-33094 Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow… Nuc M15 Laptop Kit Keyboard Led Service Driver Pack 1.0.0.4+ Fix from $1,9502021-11-17 HIGH 7.8 CVE-2021-42954 Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is v… Manageengine Remote Access Plus 10.1.2121.1+ Fix from $1,9502021-11-17 HIGH 7.8 CVE-2021-42955 Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because… Manageengine Remote Access Plus 10.1.2132+ Fix from $1,9502021-11-17 MEDIUM 5.3 CVE-2020-4146 IBM Security SiteProtector System 3.1.1 could allow a remote attacker to obtain sensitive information, caused by missing 'HttpOnly' flag. A remote at… Security Siteprotector System Mitigation only Fix from $1,6002021-11-12 HIGH 7.8 CVE-2021-37207 A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific … Sentron Powermanager 3 after 3.6 Fix from $1,9502021-11-09 CRITICAL 9.8 CVE-2021-41170 neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template eng… Neoan3 Template 1.1.1+ Fix from $2,3002021-11-08 MEDIUM 5.3 CVE-2021-20526 IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote at… Planning Analytics Patch available Fix from $1,6002021-10-27 CRITICAL 9.8 CVE-2021-41589 In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when r… Build Cache Node 10.0 / 2021.3+ Fix from $2,3002021-10-27 HIGH 7.8 CVE-2021-37364 OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/… Openclinic Ga No fix yet Fix from $1,9502021-10-26 HIGH 7.8 CVE-2021-40343 An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileg… Nagios Xi No fix yet Fix from $1,9502021-10-26 HIGH 8.8 CVE-2021-38475 The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions. Versiondog 8.0.0+ Fix from $1,9502021-10-22 MEDIUM 5.5 CVE-2021-31377 An Incorrect Permission Assignment for Critical Resource vulnerability of a certain file in the filesystem of Junos OS allows a local authenticated a… Junos Mitigation only Fix from $1,6002021-10-19 MEDIUM 6.1 CVE-2021-26589 A potential security vulnerability has been identified in HPE Superdome Flex Servers. The vulnerability could be remotely exploited to allow Cross Si… Superdome Flex Firmware 3.40.106+ Fix from $1,6002021-10-19 MEDIUM 5.4 CVE-2021-41802 HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with… Vault 1.7.5 / 1.8.4+ Fix from $1,6002021-10-08