Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Transcend Network Management System CRITICAL 9.0
CVE-2024-25660

The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized fil…

Mitigation only
Fix from $2,300 2024-10-01
Elabftw HIGH 8.8
CVE-2024-25632

eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privi…

Fix: 5.1.0+
Fix from $1,950 2024-10-01
Unclassified HIGH 7.5
CVE-2024-46511

LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attacker to execute arbitrary code …

Mitigation only
Fix from $1,950 2024-09-30
Emlog MEDIUM 6.3
CVE-2024-46540

A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloa…

Fix: 2.3.15+
Fix from $1,600 2024-09-30
Online Eyewear Shop CRITICAL 9.8
CVE-2024-9082

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functional…

No fix yet
Fix from $2,300 2024-09-22
Unclassified HIGH 8.8
CVE-2024-22303

Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.

Mitigation only
Fix from $1,950 2024-09-17
Unclassified HIGH 8.8
CVE-2024-21743

Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a throu…

Mitigation only
Fix from $1,950 2024-09-17
Post Grid HIGH 8.8
CVE-2024-8253EPSS 9%

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the pl…

Fix: 2.2.91+
Fix from $1,950 2024-09-11
Mq Operator HIGH 8.8
CVE-2024-40681

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security re…

Fix: after 3.2.3
Fix from $1,950 2024-09-07
Powerscale Onefs MEDIUM 6.7
CVE-2024-39579

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local high privileged attacker cou…

Fix: 9.7.1.2+
Fix from $1,600 2024-08-31
Netiq Access Manager HIGH 7.5
CVE-2024-4555

Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affec…

Fix: 5.0.4.1+
Fix from $1,950 2024-08-28
Mage Ai HIGH 8.8
CVE-2024-45187

Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically gi…

Mitigation only
Fix from $1,950 2024-08-23
Power Manager HIGH 8.8
CVE-2024-39576

Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local a…

Fix: 3.16.0+
Fix from $1,950 2024-08-22
Litespeed Cache CRITICAL 9.8
CVE-2024-28000EPSS 68%

Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a t…

Fix: 6.4+
Fix from $2,300 2024-08-21
Unclassified MEDIUM 5.4
CVE-2024-6322

Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is grante…

Mitigation only
Fix from $1,600 2024-08-20
Android HIGH 7.8
CVE-2024-34738

In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due to a logi…

Patch available
Fix from $1,950 2024-08-15
Elabftw MEDIUM 5.4
CVE-2024-25633

eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to create new user accoun…

Fix: 5.0.0+
Fix from $1,600 2024-08-15
Meeting Software Development Kit MEDIUM 6.7
CVE-2024-42441

Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS …

Fix: 6.1.5+
Fix from $1,600 2024-08-14
Woffice CRITICAL 9.8
CVE-2024-43153

Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10.

Fix: 5.4.12+
Fix from $2,300 2024-08-13
Sprecon E Cp 2500 Firmware MEDIUM 6.5
CVE-2024-6758

Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low privileges to save unauthorized …

Fix: 8.71j+
Fix from $1,600 2024-08-12
Skysea Client View HIGH 7.8
CVE-2024-41139

Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where th…

Fix: 19.300.09h+
Fix from $1,950 2024-07-29
Wechat HIGH 8.8
CVE-2024-40433

Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.

No fix yet
Fix from $1,950 2024-07-26
Unclassified HIGH 8.4
CVE-2024-36534

Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Mitigation only
Fix from $1,950 2024-07-24
Otrs HIGH 7.5
CVE-2024-23794

An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an age…

Fix: 2024.5.2+
Fix from $1,950 2024-07-15
Unclassified CRITICAL 9.8
CVE-2024-37927

Incorrect Privilege Assignment vulnerability in NooTheme Jobmonster noo-jobmonster allows Privilege Escalation.This issue affects Jobmonster: from n/…

Mitigation only
Fix from $2,300 2024-07-12
Android HIGH 7.8
CVE-2024-31315

In multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the Device & app notifications sett…

Patch available
Fix from $1,950 2024-07-09
Unclassified MEDIUM 6.6
CVE-2024-38278

A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.9.0), RUGGEDCOM RMC8388NC V5.X (All versions < V5.9.0), RUGGEDCOM RS…

Mitigation only
Fix from $1,600 2024-07-09
Powerscale Onefs MEDIUM 6.7
CVE-2024-37132

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high privileged attacker with local…

Fix: 9.5.1.0 / 9.7.1.0+
Fix from $1,600 2024-07-02
Powerscale Onefs MEDIUM 6.7
CVE-2024-37134

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could…

Fix: 9.5.1.0 / 9.7.1.0+
Fix from $1,600 2024-07-02
Mq HIGH 8.8
CVE-2024-31912

IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assi…

Mitigation only
Fix from $1,950 2024-06-28