Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Suitecrm HIGH 8.8
CVE-2025-64489

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 thr…

Fix: 7.14.8 / 8.9.1+
Fix from $1,950 2025-11-08
Kubevirt MEDIUM 5.3
CVE-2025-64436

KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, su…

Fix: after 1.6.1
Fix from $1,600 2025-11-07
Clipbucket CRITICAL 9.0
CVE-2025-64338

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collecti…

Fix: 5.5.2-157+
Fix from $2,300 2025-11-07
Clipbucket MEDIUM 5.4
CVE-2025-64336

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is vulnerable to stored Cross-sit…

Fix: 5.5.2-147+
Fix from $1,600 2025-11-07
Devolutions Server HIGH 8.8
CVE-2025-12485

Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another …

Fix: 2025.2.17.0 / 2025.3.6.0+
Fix from $1,950 2025-11-06
Cloudlink HIGH 7.2
CVE-2025-46364

Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain…

Fix: 8.1.1+
Fix from $1,950 2025-11-05
Unclassified MEDIUM 5.8
CVE-2025-12683

The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a N…

Mitigation only
Fix from $1,600 2025-11-04
Nagios Xi HIGH 7.2
CVE-2024-13997

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrat…

Fix: 2024+
Fix from $1,950 2025-11-03
Unclassified CRITICAL 9.8
CVE-2025-8900

The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. This is due to the plugin allowi…

Mitigation only
Fix from $2,300 2025-11-03
Unclassified CRITICAL 9.8
CVE-2025-8489EPSS 9%

The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalat…

Mitigation only
Fix from $2,300 2025-10-31
Veeam Agent For Windows HIGH 7.8
CVE-2025-48982

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a m…

Fix: 6.3.2.1302+
Fix from $1,950 2025-10-31
Nagios Xi HIGH 7.2
CVE-2024-14009

Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an…

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 8.8
CVE-2024-14004

Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenti…

Fix: 2024+
Fix from $1,950 2025-10-30
Unclassified HIGH 8.8
CVE-2025-61429

An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request.

No fix yet
Fix from $1,950 2025-10-29
Blu Ic2 Firmware CRITICAL 9.8
CVE-2025-12424

Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

Fix: 1.20+
Fix from $2,300 2025-10-28
Blu Ic2 Firmware HIGH 7.8
CVE-2025-12425

Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

Fix: 1.20+
Fix from $1,950 2025-10-28
Unclassified HIGH 7.5
CVE-2025-1037

By making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user level shell commands can enabl…

Mitigation only
Fix from $1,950 2025-10-28
Unclassified MEDIUM 5.3
CVE-2021-43768

In Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via the COM interface running in mb…

Mitigation only
Fix from $1,600 2025-10-24
Unclassified HIGH 8.1
CVE-2025-11086

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up …

Mitigation only
Fix from $1,950 2025-10-22
Vm Virtualbox MEDIUM 6.0
CVE-2025-62592

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7…

Mitigation only
Fix from $1,600 2025-10-21
Vm Virtualbox MEDIUM 6.5
CVE-2025-61759

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7…

Mitigation only
Fix from $1,600 2025-10-21
Fr307 M2 Firmware CRITICAL 9.8
CVE-2025-7851

An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.

Fix: 1.0.3 / 1.1.4+
Fix from $2,300 2025-10-21
Unclassified HIGH 7.3
CVE-2025-6042

The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation in al…

Mitigation only
Fix from $1,950 2025-10-15
Academy Lms MEDIUM 6.5
CVE-2025-56747

Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authen…

Fix: after 5.13
Fix from $1,600 2025-10-14
Factorytalk Linx HIGH 7.8
CVE-2025-9068

A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx.…

Fix: 6.50+
Fix from $1,950 2025-10-14
Factorytalk Linx HIGH 7.8
CVE-2025-9067

A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credent…

Fix: 6.50+
Fix from $1,950 2025-10-14
Unclassified CRITICAL 9.8
CVE-2025-11533

The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. This is due to the process_reg…

Mitigation only
Fix from $2,300 2025-10-11
Unclassified MEDIUM 6.5
CVE-2025-61152

python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious act…

No fix yet
Fix from $1,600 2025-10-10
Azure Playfab CRITICAL 9.8
CVE-2025-59247

Azure PlayFab Elevation of Privilege Vulnerability

No fix yet
Fix from $2,300 2025-10-09
Unclassified HIGH 8.8
CVE-2025-11561

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, t…

Mitigation only
Fix from $1,950 2025-10-09