Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.8 CVE-2020-9470 An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may vi… Wing Ftp Server after 6.2.5 Fix from $1,9502020-03-07 HIGH 7.8 CVE-2020-8635 Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local… Wing Ftp Server No fix yet Fix from $1,9502020-03-07 HIGH 7.8 CVE-2020-4278 IBM Platform LSF 9.1 and 10.1, IBM Spectrum LSF Suite 10.2, and IBM Spectrum Suite for HPA 10.2 could allow a local user to escalate their privileges… Platform Lsf Patch available Fix from $1,9502020-03-05 CRITICAL 9.4 CVE-2020-8768 An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. There is an insecure mechanis… Ilc 2050 Bi Firmware 1.2.3+ Fix from $2,3002020-02-17 HIGH 7.8 CVE-2020-1704 An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the opens… Openshift Service Mesh 1.0.8+ Fix from $1,9502020-02-17 CRITICAL 9.8 CVE-2020-9024 Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and… Vantage Velocity Firmware No fix yet Fix from $2,3002020-02-17 MEDIUM 5.4 CVE-2020-7050 Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatic… Codoforum after 4.8.4 Fix from $1,6002020-02-15 HIGH 8.1 CVE-2019-11215 In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.data… Itop after 2.6.0 Fix from $1,9502020-02-14 HIGH 7.8 CVE-2020-0563 Improper permissions in the installer for Intel(R) MPSS before version 3.8.6 may allow an authenticated user to potentially enable escalation of priv… Manycore Platform Software Stack 3.8.6+ Fix from $1,9502020-02-13 MEDIUM 6.1 CVE-2020-7051 Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lac… Codoforum after 4.8.4 Fix from $1,6002020-02-13 HIGH 7.8 CVE-2020-0668EPSS 26% An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privile… Windows 10 Patch available Fix from $1,9502020-02-11 HIGH 8.0 CVE-2019-13321 This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User inte… Mi Browser 10.4.0+ Fix from $1,9502020-02-10 MEDIUM 5.3 CVE-2011-4912 Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass. Joomla\! after 1.5.13 Fix from $1,6002020-02-04 HIGH 7.8 CVE-2019-20358 Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the… Anti Threat Toolkit after 1.62.0.1218 Fix from $1,9502020-01-30 HIGH 7.8 CVE-2019-7656 A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges to root. T… Streaming Engine after 4.8.0 Fix from $1,9502020-01-29 HIGH 7.8 CVE-2019-19363 An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation.… Generic Pcl5 Driver 4.26+ Fix from $1,9502020-01-24 MEDIUM 5.5 CVE-2019-19894 In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. An authenticated attacker (non… Easyinstall No fix yet Fix from $1,6002020-01-23 HIGH 7.8 CVE-2019-19895 In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker c… Easyinstall No fix yet Fix from $1,9502020-01-23 CRITICAL 9.8 CVE-2012-2087 ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface. Ispconfig No fix yet Fix from $2,3002020-01-23 MEDIUM 5.5 CVE-2019-14629 Improper permissions in Intel(R) DAAL before version 2020 Gold may allow an authenticated user to potentially enable information disclosure via local… Data Analytics Acceleration Library 2020+ Fix from $1,6002020-01-17 HIGH 8.8 CVE-2019-3683 The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/k… Openstack Cloud 2019-02-18+ Fix from $1,9502020-01-17 HIGH 7.8 CVE-2019-20327 Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrappe… Centreon after 19.10 Fix from $1,9502020-01-16 HIGH 7.8 CVE-2019-16784 In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software usin… Pyinstaller 3.6+ Fix from $1,9502020-01-14 MEDIUM 5.5 CVE-2019-19727 SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions. Slurm 18.08.9 / 19.05.5+ Fix from $1,6002020-01-13 MEDIUM 6.1 CVE-2019-19736 MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potent… Yetishare after 4.5.3 Fix from $1,6002019-12-30 HIGH 7.8 CVE-2019-3467 Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive A… Debian Lan Config 0.26 / 2.11.10+ Fix from $1,9502019-12-23 CRITICAL 9.0 CVE-2019-19915 The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or i… 301 Redirects 2.45+ Fix from $2,3002019-12-19 MEDIUM 5.5 CVE-2019-19341 A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both … Ansible Tower 3.6.2+ Fix from $1,6002019-12-19 CRITICAL 9.8 CVE-2019-8256 ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitat… Coldfusion Mitigation only Fix from $2,3002019-12-19 HIGH 7.8 CVE-2019-19882 shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid p… Shadow Patch available Fix from $1,9502019-12-18