Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.8 CVE-2020-12302 Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user to potentially enable escala… Driver \& Support Assistant 20.7.26.7+ Fix from $1,9502020-10-05 HIGH 7.5 CVE-2020-26106 cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558). Cpanel 88.0.3+ Fix from $1,9502020-09-25 HIGH 7.8 CVE-2020-17365 Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially e… Hotspot Shield after 10.3.0 Fix from $1,9502020-09-24 MEDIUM 6.0 CVE-2020-3503 A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access … Ios Xe Mitigation only Fix from $1,6002020-09-24 CRITICAL 9.8 CVE-2020-12842 ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php. Ismartgate Pro Firmware No fix yet Fix from $2,3002020-09-24 CRITICAL 9.8 CVE-2020-12838 ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php. Ismartgate Pro Firmware No fix yet Fix from $2,3002020-09-24 CRITICAL 9.8 CVE-2020-12839 ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php. Ismartgate Pro Firmware No fix yet Fix from $2,3002020-09-24 HIGH 7.8 CVE-2020-25826 PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe. Pingid Integration For Windows Login 2.4.2+ Fix from $1,9502020-09-23 HIGH 7.8 CVE-2020-16202 WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution wi… Webaccess 9.0.1+ Fix from $1,9502020-09-22 HIGH 7.8 CVE-2020-11855 An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow lo… Operation Bridge Reporter after 10.40 Fix from $1,9502020-09-22 HIGH 8.8 CVE-2020-15776 An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as Http… Enterprise after 2020.2.4 Fix from $1,9502020-09-18 MEDIUM 6.1 CVE-2014-10402 An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed … Dbi after 1.643 Fix from $1,6002020-09-16 MEDIUM 5.5 CVE-2020-10781 A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/cla… Linux Kernel 5.8.0+ Fix from $1,6002020-09-16 MEDIUM 6.1 CVE-2014-10401 An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed v… Dbi 1.632+ Fix from $1,6002020-09-11 HIGH 7.8 CVE-2020-7314 Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac prior t… Mcafee Agent 5.6.6+ Fix from $1,9502020-09-10 HIGH 7.8 CVE-2020-23834 Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by r… Barracudadrive No fix yet Fix from $1,9502020-09-04 HIGH 8.8 CVE-2020-5369 Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale OneFS version 9.0.0 contain a privilege escalation vulnerability. An authent… Emc Isilon Onefs Mitigation only Fix from $1,9502020-09-02 CRITICAL 9.8 CVE-2020-24355 Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by insecure permissions which allows … Vmg5313 B30b Firmware after 5.13 Fix from $2,3002020-09-02 MEDIUM 6.5 CVE-2020-17402 This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4 (47270). An attacke… Parallels Desktop 16.0.0+ Fix from $1,6002020-08-25 HIGH 8.8 CVE-2020-5417 Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is tr… Capi Release 1.97.0 / 13.12.0+ Fix from $1,9502020-08-21 HIGH 7.1 CVE-2020-24394 In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks… Linux Kernel 5.7.8+ Fix from $1,9502020-08-19 HIGH 7.8 CVE-2020-5385 Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of… Encryption 2.8 / 10.8+ Fix from $1,9502020-08-18 HIGH 7.8 CVE-2020-0559 Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticat… Ac 3165 Firmware 21.40.5.1+ Fix from $1,9502020-08-13 HIGH 8.8 CVE-2020-8731 Incorrect execution-assigned permissions in the file system for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 m… Server Board S2600wt Firmware 1.59+ Fix from $1,9502020-08-13 HIGH 7.8 CVE-2020-6295 Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential informat… Adaptive Server Enterprise Mitigation only Fix from $1,9502020-08-12 MEDIUM 5.5 CVE-2020-4631 IBM Spectrum Protect Plus 10.1.0 through 10.1.6 agent files, in non-default configurations, on Windows are assigned access to everyone with full cont… Spectrum Protect Plus after 10.1.6 Fix from $1,6002020-08-04 HIGH 7.8 CVE-2019-19455 Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamin… Streaming Engine 4.8.5+ Fix from $1,9502020-08-03 HIGH 7.5 CVE-2020-13915 Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via a… Unleashed Firmware after 200.7.10.102.92 Fix from $1,9502020-07-28 MEDIUM 5.0 CVE-2014-1422 In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the applic… Trust Store \(ubuntu\) 1.1.0+ Fix from $1,6002020-07-22 CRITICAL 9.8 CVE-2020-9671 Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead… Creative Cloud Desktop Application after 5.1 Fix from $2,3002020-07-17