Vulnerability index

Browse CVEs

933 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
CRITICAL 9.0 CVE-2024-25660 The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized fil… Transcend Network Management System Mitigation only Fix from $2,3002024-10-01 HIGH 8.8 CVE-2024-25632 eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privi… Elabftw 5.1.0+ Fix from $1,9502024-10-01 HIGH 7.5 CVE-2024-46511 LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attacker to execute arbitrary code … Mitigation only Fix from $1,9502024-09-30 MEDIUM 6.3 CVE-2024-46540 A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloa… Emlog 2.3.15+ Fix from $1,6002024-09-30 CRITICAL 9.8 CVE-2024-9082 A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as critical. Affected by this issue is some unknown functional… Online Eyewear Shop No fix yet Fix from $2,3002024-09-22 HIGH 8.8 CVE-2024-22303 Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4. Mitigation only Fix from $1,9502024-09-17 HIGH 8.8 CVE-2024-21743 Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a throu… Mitigation only Fix from $1,9502024-09-17 HIGH 8.8 CVE-2024-8253EPSS 9% The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the pl… Post Grid 2.2.91+ Fix from $1,9502024-09-11 HIGH 8.8 CVE-2024-40681 IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, to bypass security re… Mq Operator after 3.2.3 Fix from $1,9502024-09-07 MEDIUM 6.7 CVE-2024-39579 Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local high privileged attacker cou… Powerscale Onefs 9.7.1.2+ Fix from $1,6002024-08-31 HIGH 7.5 CVE-2024-4555 Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affec… Netiq Access Manager 5.0.4.1+ Fix from $1,9502024-08-28 HIGH 8.8 CVE-2024-45187 Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically gi… Mage Ai Mitigation only Fix from $1,9502024-08-23 HIGH 8.8 CVE-2024-39576 Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local a… Power Manager 3.16.0+ Fix from $1,9502024-08-22 CRITICAL 9.8 CVE-2024-28000EPSS 68% Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a t… Litespeed Cache 6.4+ Fix from $2,3002024-08-21 MEDIUM 5.4 CVE-2024-6322 Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is grante… Mitigation only Fix from $1,6002024-08-20 HIGH 7.8 CVE-2024-34738 In multiple functions of AppOpsService.java, there is a possible way for unprivileged apps to read their own restrictRead app-op states due to a logi… Android Patch available Fix from $1,9502024-08-15 MEDIUM 5.4 CVE-2024-25633 eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to create new user accoun… Elabftw 5.0.0+ Fix from $1,6002024-08-15 MEDIUM 6.7 CVE-2024-42441 Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS … Meeting Software Development Kit 6.1.5+ Fix from $1,6002024-08-14 CRITICAL 9.8 CVE-2024-43153 Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10. Woffice 5.4.12+ Fix from $2,3002024-08-13 MEDIUM 6.5 CVE-2024-6758 Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low privileges to save unauthorized … Sprecon E Cp 2500 Firmware 8.71j+ Fix from $1,6002024-08-12 HIGH 7.8 CVE-2024-41139 Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where th… Skysea Client View 19.300.09h+ Fix from $1,9502024-07-29 HIGH 8.8 CVE-2024-40433 Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component. Wechat No fix yet Fix from $1,9502024-07-26 HIGH 8.4 CVE-2024-36534 Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token. Mitigation only Fix from $1,9502024-07-24 HIGH 7.5 CVE-2024-23794 An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escalation. This flaw allows an age… Otrs 2024.5.2+ Fix from $1,9502024-07-15 CRITICAL 9.8 CVE-2024-37927 Incorrect Privilege Assignment vulnerability in NooTheme Jobmonster noo-jobmonster allows Privilege Escalation.This issue affects Jobmonster: from n/… Mitigation only Fix from $2,3002024-07-12 HIGH 7.8 CVE-2024-31315 In multiple functions of ManagedServices.java, there is a possible way to hide an app with notification access in the Device & app notifications sett… Android Patch available Fix from $1,9502024-07-09 MEDIUM 6.6 CVE-2024-38278 A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.9.0), RUGGEDCOM RMC8388NC V5.X (All versions < V5.9.0), RUGGEDCOM RS… Mitigation only Fix from $1,6002024-07-09 MEDIUM 6.7 CVE-2024-37132 Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high privileged attacker with local… Powerscale Onefs 9.5.1.0 / 9.7.1.0+ Fix from $1,6002024-07-02 MEDIUM 6.7 CVE-2024-37134 Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could… Powerscale Onefs 9.5.1.0 / 9.7.1.0+ Fix from $1,6002024-07-02 HIGH 8.8 CVE-2024-31912 IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assi… Mq Mitigation only Fix from $1,9502024-06-28