Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.8 CVE-2021-21567 Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and… Powerscale Onefs Patch available Fix from $1,9502021-08-10 HIGH 7.8 CVE-2021-32577 Acronis True Image prior to 2021 Update 5 for Windows allowed local privilege escalation due to insecure folder permissions. True Image Mitigation only Fix from $1,9502021-08-05 HIGH 7.8 CVE-2021-30577 Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation … Chrome 92.0.4515.107+ Fix from $1,9502021-08-03 HIGH 7.8 CVE-2021-32463 An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS), Worry-Free Business Securit… Apex One Patch available Fix from $1,9502021-07-20 MEDIUM 6.3 CVE-2021-32760 containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted c… Fedora 1.4.8 / 1.5.4+ Fix from $1,6002021-07-19 HIGH 7.8 CVE-2021-35449 The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and be… G2 Driver after 4.2.1.0 Fix from $1,9502021-07-19 HIGH 8.8 CVE-2021-25318 A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have… Rancher 2.4.16 / 2.5.9+ Fix from $1,9502021-07-15 HIGH 7.8 CVE-2021-31859 Incorrect privileges in the MU55 FlexiSpooler service in YSoft SafeQ 6 6.0.55 allows local user privilege escalation by overwriting the executable fi… Safeq Mitigation only Fix from $1,9502021-07-14 HIGH 7.8 CVE-2020-0417 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to… Android Patch available Fix from $1,9502021-07-14 HIGH 8.8 CVE-2021-20423 IBM Cloud Pak for Applications 4.3 could allow an authenticated user gain escalated privilesges due to improper application permissions. IBM X-Force … Cloud Pak For Applications 4.3.1+ Fix from $1,9502021-07-13 HIGH 8.8 CVE-2021-31894 A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All … Simatic Pcs 7 Firmware 5.4 / 5.7+ Fix from $1,9502021-07-13 HIGH 7.8 CVE-2021-22921EPSS 7% Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions on Windows platforms. More s… Node.js 1.0.1.1 / 12.22.2+ Fix from $1,9502021-07-12 HIGH 7.8 CVE-2021-34110 WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file tha… Winwaste.net No fix yet Fix from $1,9502021-07-08 MEDIUM 5.3 CVE-2021-20416 IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set th… Guardium Data Encryption Patch available Fix from $1,6002021-07-07 MEDIUM 6.5 CVE-2021-32526 Incorrect permission assignment for critical resource vulnerability in QSAN Storage Manager allows authenticated remote attackers to access arbitrary… Storage Manager after 3.3.1 Fix from $1,6002021-07-07 MEDIUM 5.4 CVE-2021-32729 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability exists in versions prior to … Xwiki 12.6.8 / 12.10.4+ Fix from $1,6002021-07-01 HIGH 7.8 CVE-2021-23275 The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server … Enterprise Runtime For R after 11.3.0 Fix from $1,9502021-06-29 HIGH 7.5 CVE-2021-32717 Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud Storage providers when the h… Shopware 6.4.1.1+ Fix from $1,9502021-06-24 HIGH 8.1 CVE-2020-4945 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user to overwrite arbirary files due to improper … Db2 Patch available Fix from $1,9502021-06-24 MEDIUM 5.5 CVE-2021-0552 In getEndItemSliceAction of MediaOutputSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local inf… Android Mitigation only Fix from $1,6002021-06-22 HIGH 7.8 CVE-2021-0570 In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead … Android Mitigation only Fix from $1,9502021-06-22 MEDIUM 5.5 CVE-2021-0572 In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local infor… Android Mitigation only Fix from $1,6002021-06-22 HIGH 7.8 CVE-2021-27483 ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to… Defibrillator Dashboard 2.2+ Fix from $1,9502021-06-16 HIGH 7.8 CVE-2021-0477 In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent. This could … Android Patch available Fix from $1,9502021-06-11 MEDIUM 5.5 CVE-2021-25393 Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system ui… Android No fix yet Fix from $1,6002021-06-11 HIGH 7.8 CVE-2021-23022 On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak fil… Big Ip Access Policy Manager 7.2.1.3+ Fix from $1,9502021-06-10 HIGH 7.8 CVE-2021-0055 Insecure inherited permissions for some Intel(R) NUC 9 Extreme Laptop Kit LAN Drivers before version 10.42 may allow an authenticated user to potenti… Lapqc71a Firmware 10.42+ Fix from $1,9502021-06-09 HIGH 7.8 CVE-2021-0056 Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to… Lapbc510 Firmware 1.1+ Fix from $1,9502021-06-09 HIGH 7.8 CVE-2021-0077 Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before version 2021.1.1 may allow an authenticated user to potent… Vtune Profiler 2021.1.1+ Fix from $1,9502021-06-09 HIGH 7.8 CVE-2021-0102 Insecure inherited permissions in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enabl… Unite 4.2.25031+ Fix from $1,9502021-06-09