Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Maas MEDIUM 6.5
CVE-2025-7044

An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user…

Fix: 3.3.11 / 3.4.9+
Fix from $1,600 2025-12-03
Unclassified CRITICAL 9.8
CVE-2025-13542

The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlm…

Mitigation only
Fix from $2,300 2025-12-02
Nshield 5c Firmware MEDIUM 6.8
CVE-2025-59705

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by en…

Fix: 13.6.12 / 13.9.0+
Fix from $1,600 2025-12-02
Nshield 5c Firmware HIGH 7.2
CVE-2025-59697

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by ed…

Fix: 13.6.12 / 13.9.0+
Fix from $1,950 2025-12-02
Nshield 5c Firmware CRITICAL 9.8
CVE-2025-59693

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate atta…

Fix: 13.6.12 / 13.9.0+
Fix from $2,300 2025-12-02
Wsdesk HIGH 8.8
CVE-2025-13534

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi…

Fix: 3.3.3+
Fix from $1,950 2025-12-02
Snipe It MEDIUM 5.4
CVE-2025-65621

Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's sessio…

Fix: 8.3.4+
Fix from $1,600 2025-12-01
Zentao CRITICAL 9.1
CVE-2025-13787

A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the compo…

Fix: 21.7.7+
Fix from $2,300 2025-11-30
Kvrocks MEDIUM 5.4
CVE-2025-59790

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommende…

Fix: 2.14.0+
Fix from $1,600 2025-11-28
Unclassified CRITICAL 9.8
CVE-2025-13675

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.…

Mitigation only
Fix from $2,300 2025-11-27
Unclassified HIGH 8.8
CVE-2025-13680

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the plugin allowing…

Mitigation only
Fix from $1,950 2025-11-27
Unclassified CRITICAL 9.8
CVE-2025-13540

The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the 'tiare_…

Mitigation only
Fix from $2,300 2025-11-27
Unclassified CRITICAL 9.8
CVE-2025-13538

The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the 'finda…

Mitigation only
Fix from $2,300 2025-11-27
Unclassified HIGH 7.5
CVE-2025-66314

Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACLs.This i…

Mitigation only
Fix from $1,950 2025-11-27
Unclassified CRITICAL 9.3
CVE-2025-66266

The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control. A local attacker can replace…

Mitigation only
Fix from $2,300 2025-11-26
Unclassified MEDIUM 6.9
CVE-2025-66265

CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allo…

Mitigation only
Fix from $1,600 2025-11-26
Dgx Os HIGH 7.8
CVE-2025-33188

NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware controls. A successful exploit of t…

Mitigation only
Fix from $1,950 2025-11-25
Dgx Os HIGH 7.8
CVE-2025-33187

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areas. A succe…

Mitigation only
Fix from $1,950 2025-11-25
Unclassified CRITICAL 9.8
CVE-2025-13559

The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'edukart_p…

Mitigation only
Fix from $2,300 2025-11-25
Fortiproxy MEDIUM 6.0
CVE-2025-54821

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS…

Fix: 1.6.1 / 7.6.4+
Fix from $1,600 2025-11-18
Serv U CRITICAL 9.1
CVE-2025-40548

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. …

Fix: 15.5.3+
Fix from $2,300 2025-11-18
Unclassified HIGH 8.8
CVE-2025-11923

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalation. This is due to the plugin…

Mitigation only
Fix from $1,950 2025-11-13
Windows 10 1607 HIGH 7.8
CVE-2025-59514

Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Computing Improvement Program HIGH 8.8
CVE-2025-24838

Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalat…

Fix: 2.4.11001+
Fix from $1,950 2025-11-11
Computing Improvement Program MEDIUM 6.5
CVE-2025-24863

Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an informa…

Fix: 2.4.11001+
Fix from $1,600 2025-11-11
Unclassified HIGH 8.8
CVE-2025-11168

The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5. This is due to plugin not p…

Mitigation only
Fix from $1,950 2025-11-11
Unclassified CRITICAL 9.8
CVE-2025-11457

The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in versions 0.9…

Mitigation only
Fix from $2,300 2025-11-11
Incus HIGH 7.8
CVE-2025-64507

Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment wher…

Fix: 6.0.6 / 6.19.0+
Fix from $1,950 2025-11-10
Chrome HIGH 7.5
CVE-2025-12726

Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer …

Fix: 142.0.7444.134+
Fix from $1,950 2025-11-10
Unclassified HIGH 7.7
CVE-2025-12405

An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Looker Studio user with report v…

Mitigation only
Fix from $1,950 2025-11-10