Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Decoration Management System HIGH 8.1
CVE-2024-11485

A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affected by this issue is some unkn…

Mitigation only
Fix from $1,950 2024-11-20
Unclassified CRITICAL 10.0
CVE-2024-9478

Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects up…

Mitigation only
Fix from $2,300 2024-11-20
Unclassified CRITICAL 10.0
CVE-2024-9479

Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects up…

Mitigation only
Fix from $2,300 2024-11-20
Unclassified CRITICAL 9.8
CVE-2024-52442

Incorrect Privilege Assignment vulnerability in userplus UserPlus userplus allows Privilege Escalation.This issue affects UserPlus: from n/a through …

Mitigation only
Fix from $2,300 2024-11-20
Unclassified MEDIUM 5.3
CVE-2024-11306

A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown…

Mitigation only
Fix from $1,600 2024-11-18
Unclassified HIGH 7.5
CVE-2020-25720

A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes …

Mitigation only
Fix from $1,950 2024-11-17
Unclassified MEDIUM 5.1
CVE-2024-9476

A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizati…

No fix yet
Fix from $1,600 2024-11-13
Spectrum Power 7 HIGH 7.8
CVE-2024-29119

A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected product contains several root-owned SUID binaries that c…

Fix: 24q3+
Fix from $1,950 2024-11-12
Host Agent HIGH 7.1
CVE-2024-47595

An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation t…

Mitigation only
Fix from $1,950 2024-11-12
Hospital Management System HIGH 8.1
CVE-2024-11073

A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /…

No fix yet
Fix from $1,950 2024-11-11
Data Domain Operating System HIGH 7.3
CVE-2024-45759

Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A lo…

Fix: 7.7.5.50 / 7.10.1.40+
Fix from $1,950 2024-11-08
Free Exam Hall Seating Management System CRITICAL 9.8
CVE-2024-10766

A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some u…

No fix yet
Fix from $2,300 2024-11-04
Online Institute Management System CRITICAL 9.8
CVE-2024-10764

A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /p…

No fix yet
Fix from $2,300 2024-11-04
Online Institute Management System CRITICAL 9.8
CVE-2024-10765

A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of…

No fix yet
Fix from $2,300 2024-11-04
Lr350 Firmware CRITICAL 9.1
CVE-2024-10654

A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functiona…

No fix yet
Fix from $2,300 2024-11-01
Unclassified HIGH 8.8
CVE-2024-50504

Incorrect Privilege Assignment vulnerability in webxmedia Bulk Change Role bulk-role-change allows Privilege Escalation.This issue affects Bulk Chang…

Mitigation only
Fix from $1,950 2024-10-30
Unclassified HIGH 8.8
CVE-2024-50506

Incorrect Privilege Assignment vulnerability in azexo Marketing Automation by AZEXO marketing-automation-by-azexo allows Privilege Escalation.This is…

Mitigation only
Fix from $1,950 2024-10-30
Litespeed Cache CRITICAL 9.8
CVE-2024-50550

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects…

Fix: 6.5.2+
Fix from $2,300 2024-10-29
Unclassified CRITICAL 9.8
CVE-2024-50485

Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issue affects Exam Matrix: from n…

Mitigation only
Fix from $2,300 2024-10-29
Unclassified HIGH 8.8
CVE-2024-50481

Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege Escalation.This issue affects …

Mitigation only
Fix from $1,950 2024-10-29
Intermesh 7177 Hybrid 2.0 Subscriber HIGH 7.8
CVE-2024-47904

A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < …

Fix: 7.2.12 / 8.2.12+
Fix from $1,950 2024-10-23
Gerryworks Post By Mail HIGH 8.8
CVE-2024-49608

Incorrect Privilege Assignment vulnerability in gerryworks GERRYWORKS Post by Mail gerryworks-post-by-mail allows Privilege Escalation.This issue aff…

Fix: after 1.0
Fix from $1,950 2024-10-20
Unclassified CRITICAL 9.8
CVE-2024-49322

Incorrect Privilege Assignment vulnerability in CodePassenger Job Board Manager for WordPress jemployee allows Privilege Escalation.This issue affect…

Mitigation only
Fix from $2,300 2024-10-17
Rs Members HIGH 8.8
CVE-2024-49219

Incorrect Privilege Assignment vulnerability in themexpo RS-Members rs-members allows Privilege Escalation.This issue affects RS-Members: from n/a th…

Fix: after 1.0.3
Fix from $1,950 2024-10-17
Adding Drop Down Roles In Registration CRITICAL 9.8
CVE-2024-49217

Incorrect Privilege Assignment vulnerability in madiriaashish Adding drop down roles in registration user-drop-down-roles-in-registration allows Priv…

Fix: after 1.1
Fix from $2,300 2024-10-17
Unclassified CRITICAL 9.8
CVE-2024-9863

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due …

Mitigation only
Fix from $2,300 2024-10-17
Openbao HIGH 7.2
CVE-2024-9180

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to…

Fix: 1.15.16 / 1.16.11+
Fix from $1,950 2024-10-10
Userplus HIGH 7.2
CVE-2024-9519

The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' f…

Fix: after 2.0
Fix from $1,950 2024-10-10
Secure Login MEDIUM 5.4
CVE-2024-48941

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with t…

Fix: after 3.1.4.5
Fix from $1,600 2024-10-10
Client Dashboard MEDIUM 6.5
CVE-2024-47653

This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endp…

Fix: 9.7.0+
Fix from $1,600 2024-10-04