Vulnerabilities (CVE)

Filtered by CWE-276
Total 1559 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-37351 1 Nagios 1 Nagios Xi 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.
CVE-2021-37289 1 Planex 2 Mzk-dp150n, Mzk-dp150n Firmware 2026-06-17 N/A 7.2 HIGH
Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp.
CVE-2021-37132 1 Huawei 1 Harmonyos 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that Third-party apps can obtain the complete list of Harmony apps without permission.
CVE-2021-37103 1 Huawei 2 Emui, Magic Ui 2026-06-17 2.1 LOW 5.5 MEDIUM
There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2021-37030 1 Huawei 2 Emui, Magic Ui 2026-06-17 5.0 MEDIUM 7.5 HIGH
There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
CVE-2021-37000 1 Huawei 1 Harmonyos 2026-06-17 N/A 7.7 HIGH
Some Huawei wearables have a permission management vulnerability.
CVE-2021-36990 1 Huawei 2 Emui, Magic Ui 2026-06-17 7.5 HIGH 9.8 CRITICAL
There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.
CVE-2021-36989 1 Huawei 2 Emui, Magic Ui 2026-06-17 7.5 HIGH 9.8 CRITICAL
There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.
CVE-2021-36795 1 Cohesity 1 Linux Agent 2026-06-17 4.4 MEDIUM 7.8 HIGH
A permission issue in the Cohesity Linux agent may allow privilege escalation in version 6.5.1b to 6.5.1d-hotfix10, 6.6.0a to 6.6.0b-hotfix1. An underprivileged linux user, if certain environment criteria are met, can gain additional privileges.
CVE-2021-36781 1 Opensuse 1 Factory 2026-06-17 3.6 LOW 5.9 MEDIUM
A Incorrect Default Permissions vulnerability in the parsec package of openSUSE Factory allows local attackers to imitate the service leading to DoS or clients talking to an imposter service. This issue affects: openSUSE Factory parsec versions prior to 0.8.1-1.1.
CVE-2021-36400 1 Moodle 1 Moodle 2026-06-17 N/A 5.3 MEDIUM
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
CVE-2021-36397 1 Moodle 1 Moodle 2026-06-17 N/A 5.3 MEDIUM
In Moodle, insufficient capability checks meant message deletions were not limited to the current user.
CVE-2021-36365 1 Nagios 1 Nagios Xi 2026-06-17 7.5 HIGH 9.8 CRITICAL
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
CVE-2021-36363 1 Nagios 1 Nagios Xi 2026-06-17 7.5 HIGH 9.8 CRITICAL
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
CVE-2021-35312 1 Gestionaleamica 1 Amica Prodigy 2026-06-17 7.2 HIGH 7.8 HIGH
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has incorrect permissions, allowing a local unprivileged user to replace it with a malicious file that will be executed with "LocalSystem" privileges.
CVE-2021-34395 1 Nvidia 2 Jetson Linux, Jetson Tx1 2026-06-17 4.6 MEDIUM 3.9 LOW
Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a resource from a user with local privileges, which might lead to limited information disclosure, a low risk of modifcations to data, and limited denial of service.
CVE-2021-34387 1 Nvidia 2 Jetson Linux, Jetson Tx1 2026-06-17 7.2 HIGH 6.3 MEDIUM
The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which gives write access to kernel code and data that is otherwise mapped read only.
CVE-2021-34182 1 Ttyd Project 1 Ttyd 2026-06-17 N/A 9.8 CRITICAL
An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.
CVE-2021-34164 1 Lizhifaka Project 1 Lizhifaka 2026-06-17 N/A 8.8 HIGH
Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function in the admin/index/email location.
CVE-2021-33923 1 Confluent 1 Cp-ansible 2026-06-17 2.1 LOW 5.5 MEDIUM
Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).