Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2022-01-28 CVE-2021-40389 Incorrect Default Permissions vulnerability in Advantech Deviceon/Iedge 1.0.2
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2.
local
low complexity
advantech CWE-276
7.2
2022-01-28 CVE-2021-40396 Incorrect Default Permissions vulnerability in Advantech Deviceon/Iservice 1.1.7
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7.
local
low complexity
advantech CWE-276
7.2
2022-01-28 CVE-2021-40397 Incorrect Default Permissions vulnerability in Advantech Wise-Paas/Ota 3.0.9
A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9.
network
advantech CWE-276
critical
9.3
2022-01-28 CVE-2021-40413 Incorrect Default Permissions vulnerability in Reolink Rlc-410W Firmware 3.0.0.13620121102
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102.
network
low complexity
reolink CWE-276
6.5
2022-01-28 CVE-2021-40414 Incorrect Default Permissions vulnerability in Reolink Rlc-410W Firmware 3.0.0.13620121102
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102.
network
low complexity
reolink CWE-276
5.5
2022-01-28 CVE-2021-40415 Incorrect Default Permissions vulnerability in Reolink Rlc-410W Firmware 3.0.0.13620121102
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102.
network
low complexity
reolink CWE-276
6.5
2022-01-28 CVE-2021-40416 Incorrect Default Permissions vulnerability in Reolink Rlc-410W Firmware 3.0.0.13620121102
An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102.
network
low complexity
reolink CWE-276
8.8
2022-01-26 CVE-2021-41166 Incorrect Default Permissions vulnerability in Nextcloud
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform.
network
low complexity
nextcloud CWE-276
5.0
2022-01-25 CVE-2021-46085 Incorrect Default Permissions vulnerability in Oneblog Project Oneblog
OneBlog <= 2.2.8 is vulnerable to Insecure Permissions.
network
low complexity
oneblog-project CWE-276
4.0
2022-01-25 CVE-2021-46086 Incorrect Default Permissions vulnerability in Mindskip Xzs-Mysql T3.4.0
xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions.
network
low complexity
mindskip CWE-276
5.0