Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified HIGH 8.6
CVE-2025-34251

Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU runs the Android Debug Bridge…

Mitigation only
Fix from $1,950 2025-10-07
Unclassified MEDIUM 5.1
CVE-2025-57443

FrostWire 6.14.0-build-326 for macOS contains permissive entitlements (allow-dyld-environment-variables, disable-library-validation) that allow unpri…

Mitigation only
Fix from $1,600 2025-10-02
Support Assistant HIGH 7.8
CVE-2025-10578

A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The vulnerability could potential…

Fix: 9.47.41.0+
Fix from $1,950 2025-10-01
Unclassified HIGH 8.8
CVE-2025-7779

Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True Image (macOS) before build 42…

Mitigation only
Fix from $1,950 2025-09-30
Unclassified HIGH 8.7
CVE-2025-10657

In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-conta…

Mitigation only
Fix from $1,950 2025-09-26
Drivelock CRITICAL 9.9
CVE-2025-55187

In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges.

Mitigation only
Fix from $2,300 2025-09-26
Manageengine Endpoint Central HIGH 7.8
CVE-2025-5494

ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Centra…

Fix: 11.4.2500.26 / 11.4.2508.14+
Fix from $1,950 2025-09-25
Unclassified HIGH 7.3
CVE-2025-9966

Improper privilege management vulnerability in Novakon P series allows attackers to gain root privileges if one service is compromized.This issue aff…

Mitigation only
Fix from $1,950 2025-09-23
Unclassified HIGH 7.5
CVE-2025-9038

Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Escalation.This issue affects S…

Mitigation only
Fix from $1,950 2025-09-22
Recipes MEDIUM 6.5
CVE-2025-57396

Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which resulted in…

No fix yet
Fix from $1,600 2025-09-19
Ppress HIGH 8.0
CVE-2025-54761

An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.

No fix yet
Fix from $1,950 2025-09-19
Virtual Appliance Application CRITICAL 9.8
CVE-2025-34204

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple Docker containers that run pr…

Mitigation only
Fix from $2,300 2025-09-19
Zimaos HIGH 7.8
CVE-2025-58432

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.4.1 and all prior versions, the /v2_1/fil…

Fix: after 1.4.1
Fix from $1,950 2025-09-17
Unclassified HIGH 8.8
CVE-2025-37123

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to esc…

Mitigation only
Fix from $1,950 2025-09-16
Eve X1 Server Firmware HIGH 8.8
CVE-2025-34187

Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash sc…

Fix: after 4.7.18.0
Fix from $1,950 2025-09-16
macOS HIGH 7.8
CVE-2025-43333

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to gain root privileges.

Fix: 26.0+
Fix from $1,950 2025-09-15
Online Library Management System CRITICAL 9.8
CVE-2025-57118

An issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php

No fix yet
Fix from $2,300 2025-09-15
Unclassified HIGH 8.8
CVE-2025-9059

The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.

Mitigation only
Fix from $1,950 2025-09-11
Eudskacs.sys Driver HIGH 7.8
CVE-2025-50892

The eudskacs.sys driver version 20250328 shipped with EaseUs Todo Backup 1.2.0.1 fails to properly validate privileges for I/O requests (IRP_MJ_READ/…

Mitigation only
Fix from $1,950 2025-09-10
Unclassified HIGH 7.0
CVE-2025-53913

Excessive Privileges vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 84…

Mitigation only
Fix from $1,950 2025-09-09
Unclassified HIGH 7.0
CVE-2025-53914

Excessive Privileges vulnerability in Calix GigaCenter ONT (Broadcom SoC modules) allows Privilege Abuse.This issue affects GigaCenter ONT: 844E, 844…

Mitigation only
Fix from $1,950 2025-09-09
Unclassified HIGH 7.2
CVE-2025-52915

K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate proce…

Mitigation only
Fix from $1,950 2025-09-09
Sinamics G220 Firmware CRITICAL 9.8
CVE-2025-40594

A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4…

Mitigation only
Fix from $2,300 2025-09-09
Powerscale Onefs MEDIUM 6.7
CVE-2025-43722

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privileged attacker with local acc…

Fix: 9.7.1.10 / 9.10.1.3+
Fix from $1,600 2025-09-08
Android HIGH 7.8
CVE-2025-32345

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's decept…

Mitigation only
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-26462

In AccessibilityServiceConnection.java, there is a possible background activity launch due to a logic error in the code. This could lead to local esc…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 7.8
CVE-2025-26435

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's decept…

Patch available
Fix from $1,950 2025-09-04
Android HIGH 8.8
CVE-2025-36901

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.

Mitigation only
Fix from $1,950 2025-09-04
Android CRITICAL 9.8
CVE-2025-36904

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396458384.

Mitigation only
Fix from $2,300 2025-09-04
Android CRITICAL 9.8
CVE-2025-36890

Elevation of Privilege

No fix yet
Fix from $2,300 2025-09-04