Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
CRITICAL 9.8 CVE-2020-25011 A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.… Kps2204 6 Port Managed Din Rail Programmable Serial Device Firmware Mitigation only Fix from $2,3002020-12-17 CRITICAL 9.8 CVE-2019-14480 AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or… Netcrunch after 11.0.0.5282 Fix from $2,3002020-12-16 HIGH 7.5 CVE-2020-25191 Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a function that c… Compactrio Firmware 20.5+ Fix from $1,9502020-12-11 MEDIUM 6.7 CVE-2020-7337 Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administr… Virusscan Enterprise 8.8+ Fix from $1,6002020-12-09 MEDIUM 5.3 CVE-2020-4625 IBM Cloud Pak for Security 1.3.0.1(CP4S) could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly fla… Cloud Pak For Security Patch available Fix from $1,6002020-11-30 HIGH 8.8 CVE-2020-29074 scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. Fedora Patch available Fix from $1,9502020-11-25 MEDIUM 5.5 CVE-2020-10762 An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes … Gluster Block 0.5.1+ Fix from $1,6002020-11-24 CRITICAL 9.8 CVE-2020-11831 OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1. Ovoicemanager Mitigation only Fix from $2,3002020-11-19 HIGH 7.1 CVE-2020-28914 An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a fil… Kata Containers 1.11.5+ Fix from $1,9502020-11-17 HIGH 7.8 CVE-2020-24525 Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of pri… Nuc 8 Mainstream G Kit Nuc8i5inh Firmware Mitigation only Fix from $1,9502020-11-12 HIGH 7.8 CVE-2019-11121 Improper file permissions in the installer for the Intel(R) Media SDK for Windows before version 2019 R1 may allow an authenticated user to potential… Media Sdk Patch available Fix from $1,9502020-11-12 MEDIUM 6.2 CVE-2020-16990 Azure Sphere Information Disclosure Vulnerability Azure Sphere 20.07+ Fix from $1,6002020-11-11 HIGH 7.8 CVE-2020-24367 Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later e… Bluestacks after 4.230 Fix from $1,9502020-11-10 HIGH 7.8 CVE-2020-28055 A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporatio… 32s330 Firmware No fix yet Fix from $1,9502020-11-10 HIGH 7.8 CVE-2020-3595 A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating… Sd Wan 20.1.2 / 20.3.2+ Fix from $1,9502020-11-06 MEDIUM 5.5 CVE-2020-17490 The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions. Debian Linux 2015.8.10 / 2015.8.13+ Fix from $1,6002020-11-06 HIGH 7.8 CVE-2020-15708 Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite ar… Ubuntu Linux Mitigation only Fix from $1,9502020-11-06 HIGH 7.8 CVE-2020-27992 Dr.Fone 3.0.0 allows local users to gain privileges via a Trojan horse DriverInstall.exe because %PROGRAMFILES(X86)%\Wondershare\dr.fone\Library\Driv… Dr.fone No fix yet Fix from $1,9502020-11-02 MEDIUM 6.1 CVE-2020-27658 Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easi… Router Manager 1.2.4-8081+ Fix from $1,6002020-10-29 HIGH 7.8 CVE-2020-26130 Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient access restrictions in the d… Open Tftp Server No fix yet Fix from $1,9502020-10-28 HIGH 7.8 CVE-2020-26131 Issues were discovered in Open DHCP Server (Regular) 1.75 and Open DHCP Server (LDAP Based) 0.1Beta. Due to insufficient access restrictions in the d… Open Dhcp Server No fix yet Fix from $1,9502020-10-28 HIGH 7.8 CVE-2020-26132 An issue was discovered in Home DNS Server 0.10. Due to insufficient access restrictions in the default installation directory, an attacker can eleva… Home Dns Server Mitigation only Fix from $1,9502020-10-28 HIGH 7.8 CVE-2020-26133 An issue was discovered in Dual DHCP DNS Server 7.40. Due to insufficient access restrictions in the default installation directory, an attacker can … Dual Dhcp Dns Server Mitigation only Fix from $1,9502020-10-28 HIGH 7.3 CVE-2020-10140 Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C… True Image Mitigation only Fix from $1,9502020-10-21 MEDIUM 5.5 CVE-2020-0410 In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclo… Android Patch available Fix from $1,6002020-10-14 HIGH 7.8 CVE-2020-17414 This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798. An attacker must first obtai… Foxit Reader after 10.0.1.35811 Fix from $1,9502020-10-13 HIGH 7.8 CVE-2020-17415 This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PhantomPDF 10.0.0.35798. An attacker must first o… Foxit Reader after 10.0.1.35811 Fix from $1,9502020-10-13 MEDIUM 5.5 CVE-2020-15250 In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like syste… Debian Linux 3.1.1 / 4.13.1+ Fix from $1,6002020-10-12 HIGH 8.8 CVE-2020-15838 The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions. Automate 2020.8+ Fix from $1,9502020-10-09 HIGH 8.1 CVE-2020-9048 A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated… Victor Web Client after 5.4.1 Fix from $1,9502020-10-08