Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Android HIGH 8.8
CVE-2025-36891

Elevation of privilege

No fix yet
Fix from $1,950 2025-09-04
Android CRITICAL 9.8
CVE-2025-36896

WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106.

Mitigation only
Fix from $2,300 2025-09-04
Magician MEDIUM 5.3
CVE-2025-32098

An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insec…

Fix: after 8.3.0
Fix from $1,600 2025-09-02
Vynamic Security Suite HIGH 8.1
CVE-2024-46916

Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesyst…

Fix: after 4.3.0sr06
Fix from $1,950 2025-08-29
Dcs 825l Firmware MEDIUM 6.6
CVE-2025-55582

D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries such as `dc…

No fix yet
Fix from $1,600 2025-08-27
Unclassified HIGH 7.5
CVE-2025-53105

GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk f…

Mitigation only
Fix from $1,950 2025-08-27
Unclassified HIGH 7.2
CVE-2025-36729

A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device …

Mitigation only
Fix from $1,950 2025-08-26
Unclassified HIGH 8.8
CVE-2025-6366

The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not …

Mitigation only
Fix from $1,950 2025-08-26
Mahara HIGH 8.8
CVE-2024-47853

An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with …

Fix: 23.04.9 / 24.04.5+
Fix from $1,950 2025-08-26
Unclassified HIGH 8.8
CVE-2025-5931

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.5. This is du…

Mitigation only
Fix from $1,950 2025-08-26
Langflow HIGH 8.8
CVE-2025-57760

Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers whe…

Fix: 1.5.0+
Fix from $1,950 2025-08-25
Dcs 825l Firmware HIGH 7.3
CVE-2025-55581

D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The scrip…

Fix: after 1.08.01
Fix from $1,950 2025-08-22
Unclassified MEDIUM 5.3
CVE-2025-55627

Insufficient privilege verification in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows authenticat…

Mitigation only
Fix from $1,600 2025-08-22
Openmediavault HIGH 7.8
CVE-2025-50674

An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local au…

No fix yet
Fix from $1,950 2025-08-22
Unclassified HIGH 8.5
CVE-2025-6182

The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to ins…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified HIGH 8.1
CVE-2025-8309

There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and Supp…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified MEDIUM 6.7
CVE-2025-8453

CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privileged engi…

Mitigation only
Fix from $1,600 2025-08-20
Unclassified CRITICAL 9.8
CVE-2025-6758

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' functi…

Mitigation only
Fix from $2,300 2025-08-19
Unclassified HIGH 8.8
CVE-2025-8218

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' paramet…

Mitigation only
Fix from $1,950 2025-08-19
Unclassified HIGH 8.8
CVE-2025-6080

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and incl…

Mitigation only
Fix from $1,950 2025-08-16
Sql Server 2016 HIGH 8.8
CVE-2025-49758

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…

Fix: 13.0.6465.1 / 13.0.7060.1+
Fix from $1,950 2025-08-12
Symantec Pgp Encryption CRITICAL 9.8
CVE-2025-8660

Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed.

No fix yet
Fix from $2,300 2025-08-11
Openbao HIGH 7.2
CVE-2025-54996

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions …

Fix: 2.3.2+
Fix from $1,950 2025-08-09
San Host Utilities HIGH 7.8
CVE-2025-26513

The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allo…

Fix: 8.0+
Fix from $1,950 2025-08-07
Unclassified CRITICAL 9.8
CVE-2025-6994

The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to …

Mitigation only
Fix from $2,300 2025-08-06
Unclassified CRITICAL 9.1
CVE-2025-54594

react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml Gi…

Patch available
Fix from $2,300 2025-08-06
Unclassified HIGH 8.5
CVE-2013-10052

ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured …

No fix yet
Fix from $1,950 2025-08-04
Unclassified HIGH 8.5
CVE-2012-10022

Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsu…

No fix yet
Fix from $1,950 2025-08-01
Unclassified HIGH 7.3
CVE-2025-54595

Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged helper tool bundled with the Pe…

Patch available
Fix from $1,950 2025-08-01
Unclassified CRITICAL 9.8
CVE-2025-5954

The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2…

Mitigation only
Fix from $2,300 2025-08-01