Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2021-28646
An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to take …
Apex One
Mitigation only
HIGH 7.8
CVE-2020-26155
Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which …
Block Safe Firmware
after 4.33.0
HIGH 8.8
CVE-2020-24263
Portainer 1.24.1 and earlier is affected by an insecure permissions vulnerability that may lead to remote arbitrary code execution. A non-admin user …
Portainer
after 1.24.1
HIGH 7.5
CVE-2021-28374
The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissio…
Courier Authlib
0.71.1-2+
HIGH 7.3
CVE-2021-27070
Windows 10 Update Assistant Elevation of Privilege Vulnerability
Windows 10
Patch available
MEDIUM 5.5
CVE-2021-21364
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in differen…
Swagger Codegen
2.4.19+
HIGH 7.8
CVE-2021-0372
In getMediaOutputSliceAction of RemoteMediaSlice.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local…
Android
Mitigation only
MEDIUM 6.5
CVE-2021-21177EPSS 17%
Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive informat…
Chrome
89.0.4389.72+
MEDIUM 5.5
CVE-2019-18243
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry. This may al…
Ifix
after 6.1
MEDIUM 5.5
CVE-2019-18255
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may…
Ifix
after 6.1
HIGH 7.8
CVE-2021-0109
Insecure inherited permissions for the Intel(R) SOC driver package for STK1A32SC before version 604 may allow an authenticated user to potentially en…
Compute Stick Stk1a32sc Firmware
604+
HIGH 7.8
CVE-2021-0336
In onReceive of BluetoothPermissionRequest.java, there is a possible permissions bypass due to a mutable PendingIntent. This could lead to local esca…
Android
Patch available
HIGH 7.8
CVE-2021-0334
In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains…
Android
Patch available
HIGH 7.8
CVE-2021-23874 KEV
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execu…
Total Protection
16.0.30+
HIGH 7.8
CVE-2020-26194
Dell EMC PowerScale OneFS versions 8.1.2 and 8.2.2 contain an Incorrect Permission Assignment for a Critical Resource vulnerability. This may allow a…
Emc Powerscale Onefs
Mitigation only
MEDIUM 5.5
CVE-2020-26196
Dell EMC PowerScale OneFS versions 8.1.0-9.1.0 contain a Backup/Restore Privilege implementation issue. A user with the BackupAdmin role may potentia…
Emc Powerscale Onefs
Mitigation only
MEDIUM 5.5
CVE-2020-10553
An issue was discovered in Psyprax before 3.2.2. The file %PROGRAMDATA%\Psyprax32\PPScreen.ini contains a hash for the lockscreen (aka screensaver) o…
Psyprax
3.2.2+
HIGH 7.1
CVE-2021-25276
In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world r…
Serv U
15.2.2+
HIGH 8.8
CVE-2021-3165
SmartAgent 3.1.0 allows a ViewOnly attacker to create a SuperUser account via the /#/CampaignManager/users URI.
Smartagent
No fix yet
MEDIUM 5.8
CVE-2020-17522
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissi…
Traffic Control
after 4.1.0
HIGH 8.8
CVE-2020-28482
This affects the package fastify-csrf before 3.0.0. 1. The generated cookie used insecure defaults, and did not have the httpOnly flag on: cookieOpts…
Fastify Csrf
3.0.0+
CRITICAL 9.8
CVE-2021-22850
HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform privileged functions.
Oaklouds Portal
Mitigation only
MEDIUM 5.5
CVE-2021-1126
A vulnerability in the storage of proxy server credentials of Cisco Firepower Management Center (FMC) could allow an authenticated, local attacker to…
Secure Firewall Management Center
6.7.0+
HIGH 8.1
CVE-2019-4702
IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that allows that resource to be r…
Security Guardium Data Encryption
Patch available
MEDIUM 5.5
CVE-2021-0304
In several functions of GlobalScreenshot.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local informa…
Android
Mitigation only
HIGH 7.8
CVE-2020-36154
The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory,…
Vue Testing System
No fix yet
HIGH 7.8
CVE-2020-25507
An incorrect permission assignment during the installation script of TeamworkCloud 18.0 thru 19.0 allows a local unprivileged attacker to execute arb…
Teamwork Cloud
after 19.0
HIGH 7.0
CVE-2020-28169
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account…
Debian Linux
2020-12-18+
MEDIUM 6.5
CVE-2020-24578
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a mali…
Dsl2888a Firmware
No fix yet
MEDIUM 6.5
CVE-2018-15645
Improper access control in message routing in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier allows remote authenticated users …
Odoo
after 12.0