Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.3 CVE-2021-0105 Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an authenticated user to potentially enable information disclo… Ac 9461 Firmware 22.0+ Fix from $1,9502021-06-09 HIGH 7.0 CVE-2020-1742 An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the containe… Openshift Virtualization 2.3.0+ Fix from $1,9502021-06-07 HIGH 7.8 CVE-2021-32460 The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could a… Maximum Security 2021 Mitigation only Fix from $1,9502021-06-03 MEDIUM 5.5 CVE-2020-14335 A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows… Satellite Mitigation only Fix from $1,6002021-06-02 MEDIUM 5.5 CVE-2021-23021 The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to… Nginx Controller 3.7.0+ Fix from $1,6002021-06-01 MEDIUM 6.5 CVE-2020-1701 A flaw was found in the KubeVirt main virt-handler versions before 0.26.0 regarding the access permissions of virt-handler. An attacker with access t… Kubevirt 0.26.0+ Fix from $1,6002021-05-27 HIGH 7.8 CVE-2021-31155 Failure to normalize the umask in please before 0.4 allows a local attacker to gain full root privileges if they are allowed to execute at least one … Umask 0.4+ Fix from $1,9502021-05-27 HIGH 8.8 CVE-2020-28909EPSS 5% Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges use… Fusion after 4.1.8 Fix from $1,9502021-05-24 CRITICAL 9.8 CVE-2020-28910 Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, … Nagios Xi after 5.7.5 Fix from $2,3002021-05-24 CRITICAL 9.9 CVE-2021-33509 Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStructuredText transform in a Pyt… Plone after 5.2.4 Fix from $2,3002021-05-21 HIGH 8.8 CVE-2021-31475EPSS 6% This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authe… Orion Job Scheduler Mitigation only Fix from $1,9502021-05-21 HIGH 8.8 CVE-2017-17677 BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to ru… Remedy Mid Tier Mitigation only Fix from $1,9502021-05-19 HIGH 7.8 CVE-2021-22117 RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient loc… Rabbitmq Server 3.8.16+ Fix from $1,9502021-05-18 MEDIUM 5.3 CVE-2021-20996 In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties. 0852 0303 Firmware after 1.2.3.s0 Fix from $1,6002021-05-13 HIGH 7.8 CVE-2021-31167 Windows Container Manager Service Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-05-11 MEDIUM 5.3 CVE-2021-31907 In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly. Teamcity 2020.2.2+ Fix from $1,6002021-05-11 HIGH 7.5 CVE-2021-31902 In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly. Youtrack 2020.6.6600+ Fix from $1,9502021-05-11 HIGH 8.2 CVE-2021-32101 The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerab… Openemr Mitigation only Fix from $1,9502021-05-07 HIGH 7.5 CVE-2021-31918 A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update a… Openstack Mitigation only Fix from $1,9502021-05-06 MEDIUM 5.3 CVE-2021-29247 BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie. Btcpay Server after 1.0.7.0 Fix from $1,6002021-05-05 MEDIUM 6.5 CVE-2021-20326 A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior … MongoDB 4.4.4+ Fix from $1,6002021-04-30 HIGH 8.8 CVE-2021-28269 Soyal Technology 701Client 9.0.1 is vulnerable to Insecure permissions via client.exe binary with Authenticated Users group with Full permissions. 701client No fix yet Fix from $1,9502021-04-27 HIGH 8.8 CVE-2021-22669 Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, whic… Webaccess\/scada after 9.0.1 Fix from $1,9502021-04-26 HIGH 7.1 CVE-2021-31540 Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regu… Streaming Engine after 4.8.5 Fix from $1,9502021-04-23 HIGH 7.5 CVE-2020-27568 Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. … Controller Mitigation only Fix from $1,9502021-04-21 HIGH 7.8 CVE-2021-28098 An issue was discovered in Forescout CounterACT before 8.1.4. A local privilege escalation vulnerability is present in the logging function. SecureCo… Counteract 8.1.4+ Fix from $1,9502021-04-14 HIGH 7.8 CVE-2021-22716 A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged use… C Bus Toolkit after 1.15.7 Fix from $1,9502021-04-13 HIGH 7.8 CVE-2021-25250 An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could a… Apex One No fix yet Fix from $1,9502021-04-13 HIGH 7.8 CVE-2021-25253 An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the s… Apex One Mitigation only Fix from $1,9502021-04-13 HIGH 7.8 CVE-2021-28645 An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to… Apex One Mitigation only Fix from $1,9502021-04-13