Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
HIGH 8.1 CVE-2024-11485 A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affected by this issue is some unkn… Decoration Management System Mitigation only Fix from $1,9502024-11-20 CRITICAL 10.0 CVE-2024-9478 Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects up… Mitigation only Fix from $2,3002024-11-20 CRITICAL 10.0 CVE-2024-9479 Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects up… Mitigation only Fix from $2,3002024-11-20 CRITICAL 9.8 CVE-2024-52442 Incorrect Privilege Assignment vulnerability in userplus UserPlus userplus allows Privilege Escalation.This issue affects UserPlus: from n/a through … Mitigation only Fix from $2,3002024-11-20 MEDIUM 5.3 CVE-2024-11306 A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown… Mitigation only Fix from $1,6002024-11-18 HIGH 7.5 CVE-2020-25720 A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes … Mitigation only Fix from $1,9502024-11-17 MEDIUM 5.1 CVE-2024-9476 A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizati… No fix yet Fix from $1,6002024-11-13 HIGH 7.8 CVE-2024-29119 A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected product contains several root-owned SUID binaries that c… Spectrum Power 7 24q3+ Fix from $1,9502024-11-12 HIGH 7.1 CVE-2024-47595 An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation t… Host Agent Mitigation only Fix from $1,9502024-11-12 HIGH 8.1 CVE-2024-11073 A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /… Hospital Management System No fix yet Fix from $1,9502024-11-11 HIGH 7.3 CVE-2024-45759 Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A lo… Data Domain Operating System 7.7.5.50 / 7.10.1.40+ Fix from $1,9502024-11-08 CRITICAL 9.8 CVE-2024-10766 A vulnerability, which was classified as critical, has been found in Codezips Free Exam Hall Seating Management System 1.0. This issue affects some u… Free Exam Hall Seating Management System No fix yet Fix from $2,3002024-11-04 CRITICAL 9.8 CVE-2024-10764 A vulnerability classified as critical has been found in Codezips Online Institute Management System 1.0. This affects an unknown part of the file /p… Online Institute Management System No fix yet Fix from $2,3002024-11-04 CRITICAL 9.8 CVE-2024-10765 A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of… Online Institute Management System No fix yet Fix from $2,3002024-11-04 CRITICAL 9.1 CVE-2024-10654 A vulnerability has been found in TOTOLINK LR350 up to 9.3.5u.6369 and classified as critical. Affected by this vulnerability is an unknown functiona… Lr350 Firmware No fix yet Fix from $2,3002024-11-01 HIGH 8.8 CVE-2024-50504 Incorrect Privilege Assignment vulnerability in webxmedia Bulk Change Role bulk-role-change allows Privilege Escalation.This issue affects Bulk Chang… Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-50506 Incorrect Privilege Assignment vulnerability in azexo Marketing Automation by AZEXO marketing-automation-by-azexo allows Privilege Escalation.This is… Mitigation only Fix from $1,9502024-10-30 CRITICAL 9.8 CVE-2024-50550 Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege Escalation.This issue affects… Litespeed Cache 6.5.2+ Fix from $2,3002024-10-29 CRITICAL 9.8 CVE-2024-50485 Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issue affects Exam Matrix: from n… Mitigation only Fix from $2,3002024-10-29 HIGH 8.8 CVE-2024-50481 Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege Escalation.This issue affects … Mitigation only Fix from $1,9502024-10-29 HIGH 7.8 CVE-2024-47904 A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < … Intermesh 7177 Hybrid 2.0 Subscriber 7.2.12 / 8.2.12+ Fix from $1,9502024-10-23 HIGH 8.8 CVE-2024-49608 Incorrect Privilege Assignment vulnerability in gerryworks GERRYWORKS Post by Mail gerryworks-post-by-mail allows Privilege Escalation.This issue aff… Gerryworks Post By Mail after 1.0 Fix from $1,9502024-10-20 CRITICAL 9.8 CVE-2024-49322 Incorrect Privilege Assignment vulnerability in CodePassenger Job Board Manager for WordPress jemployee allows Privilege Escalation.This issue affect… Mitigation only Fix from $2,3002024-10-17 HIGH 8.8 CVE-2024-49219 Incorrect Privilege Assignment vulnerability in themexpo RS-Members rs-members allows Privilege Escalation.This issue affects RS-Members: from n/a th… Rs Members after 1.0.3 Fix from $1,9502024-10-17 CRITICAL 9.8 CVE-2024-49217 Incorrect Privilege Assignment vulnerability in madiriaashish Adding drop down roles in registration user-drop-down-roles-in-registration allows Priv… Adding Drop Down Roles In Registration after 1.1 Fix from $2,3002024-10-17 CRITICAL 9.8 CVE-2024-9863 The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due … Mitigation only Fix from $2,3002024-10-17 HIGH 7.2 CVE-2024-9180 A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to… Openbao 1.15.16 / 1.16.11+ Fix from $1,9502024-10-10 HIGH 7.2 CVE-2024-9519 The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' f… Userplus after 2.0 Fix from $1,9502024-10-10 MEDIUM 5.4 CVE-2024-48941 The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with t… Secure Login after 3.1.4.5 Fix from $1,6002024-10-10 MEDIUM 6.5 CVE-2024-47653 This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endp… Client Dashboard 9.7.0+ Fix from $1,6002024-10-04