Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2022-01-24 CVE-2022-22296 Incorrect Default Permissions vulnerability in Hospital'S Patient Records Management System Project Hospital'S Patient Records Management System 1.0
Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id parameter in manage_user endpoint.
5.0
2022-01-19 CVE-2022-21704 Incorrect Default Permissions vulnerability in multiple products
log4js-node is a port of log4js to node.js.
local
low complexity
log4js-project debian CWE-276
5.5
2022-01-14 CVE-2021-36781 Incorrect Default Permissions vulnerability in Opensuse Factory
A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service.
local
low complexity
opensuse CWE-276
4.4
2022-01-12 CVE-2021-43860 Incorrect Default Permissions vulnerability in multiple products
Flatpak is a Linux application sandboxing and distribution framework.
local
low complexity
flatpak fedoraproject redhat debian CWE-276
8.6
2022-01-10 CVE-2021-40004 Incorrect Default Permissions vulnerability in Huawei Harmonyos
The cellular module has a vulnerability in permission management.
network
low complexity
huawei CWE-276
5.0
2022-01-10 CVE-2021-45003 Incorrect Default Permissions vulnerability in Laundry Booking Management System Project Laundry Booking Management System 1.0
Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload.
7.5
2022-01-03 CVE-2021-37132 Incorrect Default Permissions vulnerability in Huawei Harmonyos
PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that Third-party apps can obtain the complete list of Harmony apps without permission.
network
low complexity
huawei CWE-276
5.0
2022-01-03 CVE-2021-39967 Incorrect Default Permissions vulnerability in Huawei Emui, Harmonyos and Magic UI
There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei CWE-276
5.0
2021-12-27 CVE-2021-45335 Incorrect Default Permissions vulnerability in Avast Antivirus
Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to control the outcome of scans, and therefore evade detection or delete arbitrary system files.
local
low complexity
avast CWE-276
7.2
2021-12-22 CVE-2021-21910 Incorrect Default Permissions vulnerability in Advantech R-Seenet 2.4.15
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021).
local
low complexity
advantech CWE-276
7.2