Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.3
CVE-2021-0105
Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an authenticated user to potentially enable information disclo…
Ac 9461 Firmware
22.0+
HIGH 7.0
CVE-2020-1742
An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the containe…
Openshift Virtualization
2.3.0+
HIGH 7.8
CVE-2021-32460
The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could a…
Maximum Security 2021
Mitigation only
MEDIUM 5.5
CVE-2020-14335
A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows…
Satellite
Mitigation only
MEDIUM 5.5
CVE-2021-23021
The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to…
Nginx Controller
3.7.0+
MEDIUM 6.5
CVE-2020-1701
A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access t…
Kubevirt
0.26.0+
HIGH 7.8
CVE-2021-31155
Failure to normalize the umask in please before 0.4 allows a local attacker to gain full root privileges if they are allowed to execute at least one …
Umask
0.4+
HIGH 8.8
CVE-2020-28909EPSS 5%
Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges use…
Fusion
after 4.1.8
CRITICAL 9.8
CVE-2020-28910
Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, …
Nagios Xi
after 5.7.5
CRITICAL 9.9
CVE-2021-33509
Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Pyt…
Plone
after 5.2.4
HIGH 8.8
CVE-2021-31475EPSS 6%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authe…
Orion Job Scheduler
Mitigation only
HIGH 8.8
CVE-2017-17677
BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to ru…
Remedy Mid Tier
Mitigation only
HIGH 7.8
CVE-2021-22117
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient loc…
Rabbitmq Server
3.8.16+
MEDIUM 5.3
CVE-2021-20996
In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.
0852 0303 Firmware
after 1.2.3.s0
HIGH 7.8
CVE-2021-31167
Windows Container Manager Service Elevation of Privilege Vulnerability
Windows 10
Patch available
MEDIUM 5.3
CVE-2021-31907
In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.
Teamcity
2020.2.2+
HIGH 7.5
CVE-2021-31902
In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
Youtrack
2020.6.6600+
HIGH 8.2
CVE-2021-32101
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerab…
Openemr
Mitigation only
HIGH 7.5
CVE-2021-31918
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update a…
Openstack
Mitigation only
MEDIUM 5.3
CVE-2021-29247
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.
Btcpay Server
after 1.0.7.0
MEDIUM 6.5
CVE-2021-20326
A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior …
MongoDB
4.4.4+
HIGH 8.8
CVE-2021-28269
Soyal Technology 701Client 9.0.1 is vulnerable to Insecure permissions via client.exe binary with Authenticated Users group with Full permissions.
701client
No fix yet
HIGH 8.8
CVE-2021-22669
Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, whic…
Webaccess\/scada
after 9.0.1
HIGH 7.1
CVE-2021-31540
Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regu…
Streaming Engine
after 4.8.5
HIGH 7.5
CVE-2020-27568
Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. …
Controller
Mitigation only
HIGH 7.8
CVE-2021-28098
An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureCo…
Counteract
8.1.4+
HIGH 7.8
CVE-2021-22716
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged use…
C Bus Toolkit
after 1.15.7
HIGH 7.8
CVE-2021-25250
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could a…
Apex One
No fix yet
HIGH 7.8
CVE-2021-25253
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the s…
Apex One
Mitigation only
HIGH 7.8
CVE-2021-28645
An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to…
Apex One
Mitigation only