Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Unclassified MEDIUM 5.3
CVE-2023-7270

An issue was discovered in SoftMaker Office 2024 / NX before revision 1214 and SoftMaker FreeOffice 2014 before revision 1215. FreeOffice 2021 is als…

Mitigation only
Fix from $1,600 2024-06-27
I HIGH 7.8
CVE-2024-27275

IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user withou…

Mitigation only
Fix from $1,950 2024-06-15
Virtual Gpu HIGH 7.8
CVE-2024-0085

NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A succe…

Fix: 13.11 / 16.6+
Fix from $1,950 2024-06-13
Unclassified HIGH 7.8
CVE-2024-36587

Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via overwriting the bina…

Mitigation only
Fix from $1,950 2024-06-13
Aws Deployment Framework HIGH 7.8
CVE-2024-37293

The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization.…

Fix: 4.0.0+
Fix from $1,950 2024-06-11
Userpro CRITICAL 9.8
CVE-2024-35700

Incorrect Privilege Assignment vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1.8.

Fix: 5.1.9+
Fix from $2,300 2024-06-04
Unclassified HIGH 7.2
CVE-2024-4870

The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1 due to in…

Mitigation only
Fix from $1,950 2024-06-04
Linux Kernel HIGH 7.5
CVE-2021-47241

In the Linux kernel, the following vulnerability has been resolved: ethtool: strset: fix message length calculation Outer nest for ETHTOOL_A_STRSET…

Fix: 5.10.46 / 5.12.13+
Fix from $1,950 2024-05-21
Sirv HIGH 8.8
CVE-2024-32959

Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.2.

Fix: 7.2.3+
Fix from $1,950 2024-05-17
Unclassified HIGH 8.8
CVE-2024-32507

Incorrect Privilege Assignment vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone numb…

Mitigation only
Fix from $1,950 2024-05-17
Masteriyo CRITICAL 9.8
CVE-2024-24882

Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a thr…

Fix: 1.7.3+
Fix from $2,300 2024-05-17
Instawp Connect HIGH 8.8
CVE-2024-22145

Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0…

Fix: 0.1.0.9+
Fix from $1,950 2024-05-17
Crosswork Network Services Orchestrator HIGH 7.8
CVE-2024-20389

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attac…

Mitigation only
Fix from $1,950 2024-05-16
Totalav HIGH 7.8
CVE-2024-31771

Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file

No fix yet
Fix from $1,950 2024-05-14
Poly Plantronics Hub MEDIUM 6.7
CVE-2024-27460

A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.

Fix: after 3.25.1
Fix from $1,600 2024-05-14
Vios HIGH 7.8
CVE-2024-27273

IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain d…

Mitigation only
Fix from $1,950 2024-05-07
Extremexos HIGH 8.6
CVE-2024-27453

In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine…

Fix: 22.7+
Fix from $1,950 2024-05-03
Unclassified HIGH 8.8
CVE-2023-38298

Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI to a system property that can be accessed by any loc…

Mitigation only
Fix from $1,950 2024-04-22
Unclassified HIGH 8.0
CVE-2023-38296

Various software builds for the following TCL 30Z and TCL A3X devices leak the ICCID to a system property that can be accessed by any local app on th…

Mitigation only
Fix from $1,950 2024-04-22
Masterstudy Lms CRITICAL 9.8
CVE-2024-2409

The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficie…

Fix: 3.3.2+
Fix from $2,300 2024-03-29
Flir Ax8 Firmware HIGH 8.8
CVE-2024-3013EPSS 23%

A flaw has been found in Teledyne FLIR AX8 up to 1.46.16. The impacted element is an unknown function of the file /tools/test_login.php?action=regist…

Fix: after 1.46.16
Fix from $1,950 2024-03-28
Ios Xr HIGH 7.8
CVE-2024-20320

A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Serie…

Mitigation only
Fix from $1,950 2024-03-13
Ipados HIGH 7.8
CVE-2024-23288

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4…

Fix: 10.4 / 14.4+
Fix from $1,950 2024-03-08
Couchbase Server HIGH 8.6
CVE-2023-50437

An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageClu…

Fix: 7.2.4+
Fix from $1,950 2024-02-29
GitLab MEDIUM 6.7
CVE-2023-6477

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all…

Fix: 16.7.6+
Fix from $1,600 2024-02-22
Privilege Management For Windows HIGH 7.8
CVE-2024-25083

An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiates a repair, there is an atta…

Fix: 24.1+
Fix from $1,950 2024-02-16
Android HIGH 7.8
CVE-2023-40109

In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL) due to a permissions bypass. This could lead to lo…

Patch available
Fix from $1,950 2024-02-15
Big Ip Access Policy Manager MEDIUM 6.0
CVE-2024-23976

When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing…

Fix: 15.1.9 / 16.1.4+
Fix from $1,600 2024-02-14
R08sfcpu Firmware MEDIUM 6.5
CVE-2023-6815

Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series Safety CPU R08/16/32/120SFCPU all versions and MEL…

Mitigation only
Fix from $1,600 2024-02-13
Tab M8 Hd Tb8505f Firmware HIGH 7.8
CVE-2023-5080

A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and…

Fix: 8505xs_usr_s301077_2309140036_v9.56_bmp_row / 8505f_usr_s301106_2309140042_v9.56_bmp_row+
Fix from $1,950 2024-01-19