Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Virtual Apps And Desktops HIGH 7.8
CVE-2025-6759

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS

Fix: 2503+
Fix from $1,950 2025-07-08
Support Assistant HIGH 7.8
CVE-2025-43019

A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbit…

Mitigation only
Fix from $1,950 2025-07-08
Charx Sec 3000 Firmware HIGH 7.8
CVE-2025-24006

A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.

Fix: 1.7.3+
Fix from $1,950 2025-07-08
Nessus HIGH 7.1
CVE-2025-36630

In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system file…

Fix: 10.8.5+
Fix from $1,950 2025-07-02
Unclassified CRITICAL 9.8
CVE-2025-6934EPSS 25%

The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vul…

Mitigation only
Fix from $2,300 2025-07-01
Unclassified HIGH 8.2
CVE-2025-53003

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without s…

Patch available
Fix from $1,950 2025-07-01
Neacsafe64 MEDIUM 6.5
CVE-2025-45737

An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafted IOCTL c…

Fix: 1.0.0.8+
Fix from $1,600 2025-06-27
Unclassified MEDIUM 6.5
CVE-2025-52555

Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged…

Patch available
Fix from $1,600 2025-06-26
Unclassified HIGH 8.7
CVE-2025-37101

A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an a…

Mitigation only
Fix from $1,950 2025-06-26
Memberhero CRITICAL 9.8
CVE-2025-4334

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to ins…

Fix: after 6.3
Fix from $2,300 2025-06-26
Identity Services Engine CRITICAL 10.0
CVE-2025-20282EPSS 27%

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an aff…

Mitigation only
Fix from $2,300 2025-06-25
Microscada X Sys600 HIGH 8.1
CVE-2025-39202

A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and over…

Fix: 10.7+
Fix from $1,950 2025-06-24
Visor Vision Sensors Firmware HIGH 8.4
CVE-2023-50450

An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated privileges.

Fix: 2.10.0.2+
Fix from $1,950 2025-06-23
Apex One HIGH 7.8
CVE-2025-49156

A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installation…

Fix: 14.0.0.14002 / 14.0.14492+
Fix from $1,950 2025-06-17
Apex One HIGH 7.8
CVE-2025-49157

A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected in…

Fix: 14.0.0.14002 / 14.0.14492+
Fix from $1,950 2025-06-17
Workspace HIGH 7.8
CVE-2025-4879

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Fix: 2402 / 2409+
Fix from $1,950 2025-06-17
Secure Access Client HIGH 7.8
CVE-2025-0320

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows

Fix: 25.5.1.15+
Fix from $1,950 2025-06-17
Chrome Os HIGH 7.4
CVE-2025-6177

Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code e…

Mitigation only
Fix from $1,950 2025-06-16
Authd HIGH 8.5
CVE-2025-5689

A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to…

Fix: 0.5.4+
Fix from $1,950 2025-06-16
Nessus Agent HIGH 7.8
CVE-2025-36633

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files …

Fix: 10.8.5+
Fix from $1,950 2025-06-13
Nessus Agent HIGH 7.8
CVE-2025-36631

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files…

Fix: 10.8.5+
Fix from $1,950 2025-06-13
Unclassified HIGH 8.8
CVE-2025-5491

Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a custom protocol to invoke inter…

Mitigation only
Fix from $1,950 2025-06-13
Vpn HIGH 7.8
CVE-2025-5687

A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other op…

Fix: 2.28.0+
Fix from $1,950 2025-06-11
Cubewp HIGH 8.8
CVE-2025-4315

The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.…

Fix: 1.1.24+
Fix from $1,950 2025-06-11
Cloudstack HIGH 8.8
CVE-2025-47713

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…

Fix: 4.19.3.0 / 4.20.1.0+
Fix from $1,950 2025-06-10
Cloudstack HIGH 8.8
CVE-2025-47849

A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…

Fix: 4.19.3.0 / 4.20.1.0+
Fix from $1,950 2025-06-10
Windows 10 1507 HIGH 7.8
CVE-2025-47955

Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-06-10
Windows 10 1507 HIGH 8.4
CVE-2025-33067

Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.10240.21034 / 10.0.14393.8148+
Fix from $1,950 2025-06-10
Fortios HIGH 7.2
CVE-2025-22254

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS …

Fix: 6.4.16 / 7.0.17+
Fix from $1,950 2025-06-10
Unclassified HIGH 8.6
CVE-2025-4681

Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abuse.This issue affects upKeepe…

Mitigation only
Fix from $1,950 2025-06-10