Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.8 CVE-2021-20264 An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11 containers. This flaw allows an attacker with acces… Openjdk Mitigation only Fix from $1,9502021-10-06 HIGH 7.8 CVE-2021-0692 In sendBroadcastToInstaller of FirstScreenBroadcast.java, there is a possible activity launch due to an unsafe PendingIntent. This could lead to loca… Android Patch available Fix from $1,9502021-10-06 MEDIUM 6.3 CVE-2021-41091 Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data director… Fedora 20.10.9+ Fix from $1,6002021-10-04 HIGH 7.8 CVE-2021-3747 The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner. Multipass 1.7.2+ Fix from $1,9502021-10-01 HIGH 7.8 CVE-2021-34409 It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.… Meetings 5.1.0 / 5.2.0+ Fix from $1,9502021-09-27 HIGH 7.8 CVE-2021-34410 A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook for Mac before 5.0.25611.052… Zoom Plugin For Microsoft Outlook 5.0.25611.0521+ Fix from $1,9502021-09-27 MEDIUM 5.3 CVE-2021-40066 The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and vali… Mobility 11.76 / 12.14+ Fix from $1,6002021-09-16 MEDIUM 6.8 CVE-2021-40067 The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manual… Mobility 12.14+ Fix from $1,6002021-09-16 MEDIUM 6.5 CVE-2021-39210 GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses … Glpi 9.5.6+ Fix from $1,6002021-09-15 HIGH 8.8 CVE-2021-22149 Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate rou… Enterprise Search 7.14.0+ Fix from $1,9502021-09-15 HIGH 7.8 CVE-2021-26434 Visual Studio Elevation of Privilege Vulnerability Visual Studio 2017 after 16.11 Fix from $1,9502021-09-15 MEDIUM 6.5 CVE-2021-22147 Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining… Elasticsearch 7.14.0+ Fix from $1,6002021-09-15 HIGH 8.8 CVE-2021-22148 Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their cre… Enterprise Search 7.14.0+ Fix from $1,9502021-09-15 HIGH 7.5 CVE-2021-3706 adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag Web Interface 5.6+ Fix from $1,9502021-09-15 HIGH 8.8 CVE-2021-35508 NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges via a low-privileged user accou… Aquariusnet No fix yet Fix from $1,9502021-09-01 HIGH 8.8 CVE-2020-18121 A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell. Indexhibit No fix yet Fix from $1,9502021-08-30 HIGH 7.5 CVE-2021-38154 Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, a… No fix yet Fix from $1,9502021-08-29 MEDIUM 5.5 CVE-2021-30964 An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.1, watchOS 8.3, iOS 15.2 and iPad… Ipados 8.3 / 12.1+ Fix from $1,6002021-08-24 MEDIUM 5.5 CVE-2021-30920 A permissions issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.0.1. A local attacker may be able to read sensit… macOS 12.0.1+ Fix from $1,6002021-08-24 MEDIUM 5.5 CVE-2021-30892EPSS 10% An inherited permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Cat… Mac Os X 10.15.7 / 11.6.1+ Fix from $1,6002021-08-24 HIGH 8.8 CVE-2021-38557 raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can exec… Raspap No fix yet Fix from $1,9502021-08-24 HIGH 7.8 CVE-2021-25263 Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code wit… Yandex Browser 21.9.0.390+ Fix from $1,9502021-08-17 HIGH 7.8 CVE-2021-36279 Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a u… Emc Powerscale Onefs after 9.2.2.0 Fix from $1,9502021-08-16 MEDIUM 5.5 CVE-2021-36280 Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulnerability. This could allow a u… Emc Powerscale Onefs after 9.2.1 Fix from $1,6002021-08-16 HIGH 8.8 CVE-2021-36281 Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privileged authenticated user can po… Emc Powerscale Onefs after 9.2.1 Fix from $1,9502021-08-16 HIGH 7.8 CVE-2021-37841 Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows conta… Desktop 3.6.0+ Fix from $1,9502021-08-12 MEDIUM 5.5 CVE-2021-38590 In cPanel before 96.0.8, weak permissions on web stats can lead to information disclosure (SEC-584). Cpanel 11.98.0.8+ Fix from $1,6002021-08-11 HIGH 8.8 CVE-2017-16630 In SapphireIMS 4097_1, a guest user can create a local administrator account on any system that has SapphireIMS installed, because of an Insecure Dir… Sapphireims Mitigation only Fix from $1,9502021-08-11 MEDIUM 6.5 CVE-2017-16631 In SapphireIMS 4097_1, a guest user is able to change the password of an administrative user by utilizing an Insecure Direct Object Reference (IDOR) … Sapphireims Mitigation only Fix from $1,6002021-08-11 HIGH 7.8 CVE-2021-38085 The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can ov… Pixma Tr150 Firmware after 3.71.2.10 Fix from $1,9502021-08-11