Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
MEDIUM 5.5 CVE-2021-28646 An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to take … Apex One Mitigation only Fix from $1,6002021-04-13 HIGH 7.8 CVE-2020-26155 Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which … Block Safe Firmware after 4.33.0 Fix from $1,9502021-03-18 HIGH 8.8 CVE-2020-24263 Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user … Portainer after 1.24.1 Fix from $1,9502021-03-16 HIGH 7.5 CVE-2021-28374 The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissio… Courier Authlib 0.71.1-2+ Fix from $1,9502021-03-15 HIGH 7.3 CVE-2021-27070 Windows 10 Update Assistant Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-03-11 MEDIUM 5.5 CVE-2021-21364 swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in differen… Swagger Codegen 2.4.19+ Fix from $1,6002021-03-11 HIGH 7.8 CVE-2021-0372 In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local… Android Mitigation only Fix from $1,9502021-03-10 MEDIUM 6.5 CVE-2021-21177EPSS 17% Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive informat… Chrome 89.0.4389.72+ Fix from $1,6002021-03-09 MEDIUM 5.5 CVE-2019-18243 HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry. This may al… Ifix after 6.1 Fix from $1,6002021-02-18 MEDIUM 5.5 CVE-2019-18255 HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may… Ifix after 6.1 Fix from $1,6002021-02-18 HIGH 7.8 CVE-2021-0109 Insecure inherited permissions for the Intel(R) SOC driver package for STK1A32SC before version 604 may allow an authenticated user to potentially en… Compute Stick Stk1a32sc Firmware 604+ Fix from $1,9502021-02-17 HIGH 7.8 CVE-2021-0336 In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local esca… Android Patch available Fix from $1,9502021-02-10 HIGH 7.8 CVE-2021-0334 In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains… Android Patch available Fix from $1,9502021-02-10 HIGH 7.8 CVE-2021-23874 KEV Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execu… Total Protection 16.0.30+ Fix from $1,9502021-02-10 HIGH 7.8 CVE-2020-26194 Dell EMC PowerScale OneFS versions 8.1.2 and 8.2.2 contain an Incorrect Permission Assignment for a Critical Resource vulnerability. This may allow a… Emc Powerscale Onefs Mitigation only Fix from $1,9502021-02-09 MEDIUM 5.5 CVE-2020-26196 Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue. A user with the BackupAdmin role may potentia… Emc Powerscale Onefs Mitigation only Fix from $1,6002021-02-09 MEDIUM 5.5 CVE-2020-10553 An issue was discovered in Psyprax before 3.2.2. The file %PROGRAMDATA%\Psyprax32\PPScreen.ini contains a hash for the lockscreen (aka screensaver) o… Psyprax 3.2.2+ Fix from $1,6002021-02-05 HIGH 7.1 CVE-2021-25276 In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world r… Serv U 15.2.2+ Fix from $1,9502021-02-03 HIGH 8.8 CVE-2021-3165 SmartAgent 3.1.0 allows a ViewOnly attacker to create a SuperUser account via the /#/CampaignManager/users URI. Smartagent No fix yet Fix from $1,9502021-01-26 MEDIUM 5.8 CVE-2020-17522 When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissi… Traffic Control after 4.1.0 Fix from $1,6002021-01-26 HIGH 8.8 CVE-2020-28482 This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts… Fastify Csrf 3.0.0+ Fix from $1,9502021-01-19 CRITICAL 9.8 CVE-2021-22850 HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions. Oaklouds Portal Mitigation only Fix from $2,3002021-01-19 MEDIUM 5.5 CVE-2021-1126 A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to… Secure Firewall Management Center 6.7.0+ Fix from $1,6002021-01-13 HIGH 8.1 CVE-2019-4702 IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be r… Security Guardium Data Encryption Patch available Fix from $1,9502021-01-13 MEDIUM 5.5 CVE-2021-0304 In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local informa… Android Mitigation only Fix from $1,6002021-01-11 HIGH 7.8 CVE-2020-36154 The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory,… Vue Testing System No fix yet Fix from $1,9502021-01-04 HIGH 7.8 CVE-2020-25507 An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivileged attacker to execute arb… Teamwork Cloud after 19.0 Fix from $1,9502020-12-28 HIGH 7.0 CVE-2020-28169 The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account… Debian Linux 2020-12-18+ Fix from $1,9502020-12-24 MEDIUM 6.5 CVE-2020-24578 An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a mali… Dsl2888a Firmware No fix yet Fix from $1,6002020-12-22 MEDIUM 6.5 CVE-2018-15645 Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users … Odoo after 12.0 Fix from $1,6002020-12-22