Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Bluvoyix CRITICAL 9.8
CVE-2026-22238

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this…

Mitigation only
Fix from $2,300 2026-01-14
Unclassified HIGH 7.8
CVE-2025-37186

A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA) client. Successful exploitat…

Mitigation only
Fix from $1,950 2026-01-13
Unclassified HIGH 8.8
CVE-2025-36640

A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation o…

Mitigation only
Fix from $1,950 2026-01-13
Unclassified CRITICAL 9.8
CVE-2025-14736

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is du…

Mitigation only
Fix from $2,300 2026-01-09
Mf258k Pro Firmware HIGH 8.8
CVE-2025-66315

There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an att…

Mitigation only
Fix from $1,950 2026-01-09
Rustfs CRITICAL 9.8
CVE-2026-22043

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in…

Mitigation only
Fix from $2,300 2026-01-08
Unclassified HIGH 8.6
CVE-2026-22536

The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restricti…

Mitigation only
Fix from $1,950 2026-01-07
Streampipes HIGH 8.1
CVE-2025-47411EPSS 15%

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows th…

Fix: 0.98.0+
Fix from $1,950 2026-01-01
Unclassified MEDIUM 6.7
CVE-2025-69257

theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.1.1, the application loa…

Patch available
Fix from $1,600 2025-12-30
N8n MEDIUM 5.4
CVE-2025-68697

n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task…

Fix: 2.0.0+
Fix from $1,600 2025-12-26
Xnv L6080r Firmware MEDIUM 6.5
CVE-2025-52599

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered In…

Fix: 2.23.01+
Fix from $1,600 2025-12-26
K7 Ultimate Security HIGH 7.7
CVE-2025-67826

An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antivirus can…

Mitigation only
Fix from $1,950 2025-12-22
Unclassified CRITICAL 9.8
CVE-2025-13619

The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUs…

Mitigation only
Fix from $2,300 2025-12-20
Galette CRITICAL 9.8
CVE-2025-58053

Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a s…

Fix: 1.2.0+
Fix from $2,300 2025-12-19
Ds 7104hghi F1 Firmware MEDIUM 6.2
CVE-2025-66173

There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial por…

Fix: after 4.30.122_201107
Fix from $1,600 2025-12-19
Unclassified HIGH 8.8
CVE-2023-53908

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF c…

No fix yet
Fix from $1,950 2025-12-17
Drivelock HIGH 7.8
CVE-2025-67792

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate a DriveL…

Fix: 24.1.6 / 24.2.7+
Fix from $1,950 2025-12-17
Drivelock CRITICAL 9.8
CVE-2025-67793

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" …

Fix: 25.1.6+
Fix from $2,300 2025-12-17
Drivelock CRITICAL 9.9
CVE-2025-67781

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileg…

Fix: 24.1.6 / 24.2.7+
Fix from $2,300 2025-12-17
Unclassified HIGH 7.8
CVE-2025-14252

An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, re…

Mitigation only
Fix from $1,950 2025-12-16
macOS HIGH 7.8
CVE-2025-43512

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, mac…

Fix: 14.8.3 / 15.7.3+
Fix from $1,950 2025-12-12
macOS HIGH 7.8
CVE-2025-43320

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app may be able to bypass launch …

Fix: 15.7.3+
Fix from $1,950 2025-12-12
Parse Server CRITICAL 9.8
CVE-2025-67727

Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI …

Fix: after 8.5.0
Fix from $2,300 2025-12-12
Unclassified CRITICAL 9.8
CVE-2025-13764

The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16. This is due to the 'WP_CarD…

Mitigation only
Fix from $2,300 2025-12-11
Unclassified HIGH 8.7
CVE-2025-12952

A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook editor permission are able to …

Mitigation only
Fix from $1,950 2025-12-10
Firewall Analyzer HIGH 7.8
CVE-2025-12381

Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection. A local …

Mitigation only
Fix from $1,950 2025-12-09
Harmonyos MEDIUM 5.5
CVE-2025-66324

Input verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vulnerability may affect app da…

No fix yet
Fix from $1,600 2025-12-08
Unclassified HIGH 7.6
CVE-2025-13292

A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data and access logs belonging to…

Mitigation only
Fix from $1,950 2025-12-06
Installation Manager MEDIUM 6.2
CVE-2025-55076

A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for mac…

No fix yet
Fix from $1,600 2025-12-03
Installation Manager MEDIUM 6.2
CVE-2025-62686

A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin Alliance Installation Manage…

No fix yet
Fix from $1,600 2025-12-03