Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified HIGH 8.8
CVE-2025-4601EPSS 6%

The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is…

Mitigation only
Fix from $1,950 2025-06-10
Synapse 4 HIGH 7.8
CVE-2025-27811

A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate thei…

Fix: after 4.0.86.2502180127
Fix from $1,950 2025-06-04
Unclassified HIGH 7.8
CVE-2025-26396

The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vul…

Mitigation only
Fix from $1,950 2025-06-02
Axis Os HIGH 8.8
CVE-2025-0358

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th…

Fix: 12.4.0+
Fix from $1,950 2025-06-02
Unclassified HIGH 7.8
CVE-2025-4636

Due to excessive privileges granted to the web user running the airpointer web platform, a malicious actor that gains control of the this user would …

Mitigation only
Fix from $1,950 2025-05-30
Unclassified HIGH 8.8
CVE-2024-51392

An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component

Mitigation only
Fix from $1,950 2025-05-29
Innovation HIGH 7.8
CVE-2024-40462

An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE component

No fix yet
Fix from $1,950 2025-05-22
Innovation HIGH 7.2
CVE-2024-41199

An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a cr…

No fix yet
Fix from $1,950 2025-05-22
Innovation HIGH 7.8
CVE-2024-40458

An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets.

No fix yet
Fix from $1,950 2025-05-22
Innovation HIGH 7.8
CVE-2024-40459

An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager function

No fix yet
Fix from $1,950 2025-05-22
Innovation HIGH 7.8
CVE-2024-40460

An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE

No fix yet
Fix from $1,950 2025-05-22
Innovation HIGH 7.8
CVE-2024-40461

An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE component

No fix yet
Fix from $1,950 2025-05-22
Orangehrm HIGH 7.2
CVE-2025-44040

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions …

Mitigation only
Fix from $1,950 2025-05-21
macOS MEDIUM 5.5
CVE-2025-24183

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local user may …

Fix: 13.7.3 / 14.7.3+
Fix from $1,600 2025-05-19
Insightiq CRITICAL 9.8
CVE-2025-30475

Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote…

Fix: 6.0.0+
Fix from $2,300 2025-05-15
Sharepoint Server HIGH 7.8
CVE-2025-29976

Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.

Fix: 16.0.18526.20286+
Fix from $1,950 2025-05-13
Windows 10 1507 HIGH 7.0
CVE-2025-27468

Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Ipados HIGH 7.8
CVE-2025-31222

A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, macOS Sonoma 14.7.6, mac…

Fix: 2.5 / 11.5+
Fix from $1,950 2025-05-12
macOS HIGH 7.8
CVE-2025-24258

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6.…

Fix: 13.7.6 / 14.7.6+
Fix from $1,950 2025-05-12
Unclassified HIGH 8.7
CVE-2024-8100

On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on C…

Mitigation only
Fix from $1,950 2025-05-08
Unclassified CRITICAL 10.0
CVE-2025-0505

On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the Cloud…

Mitigation only
Fix from $2,300 2025-05-08
Unclassified HIGH 8.8
CVE-2025-4335

The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.7.1. This is …

Mitigation only
Fix from $1,950 2025-05-07
Unclassified HIGH 8.8
CVE-2025-3852

The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to …

Mitigation only
Fix from $1,950 2025-05-07
Unclassified HIGH 8.7
CVE-2025-47420

266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.

Mitigation only
Fix from $1,950 2025-05-06
Mstore Api HIGH 7.3
CVE-2025-3438

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up …

Fix: 4.17.5+
Fix from $1,950 2025-05-02
Xwiki CRITICAL 9.0
CVE-2025-32974

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights an…

Fix: 15.10.8 / 16.2.0+
Fix from $2,300 2025-04-30
Unclassified CRITICAL 9.8
CVE-2025-25962

An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function

Mitigation only
Fix from $2,300 2025-04-29
Firefox HIGH 7.1
CVE-2025-4085

An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate priv…

Fix: 138.0+
Fix from $1,950 2025-04-29
Desktop HIGH 7.8
CVE-2025-3224

A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate…

Fix: 4.41.0+
Fix from $1,950 2025-04-28
Zxcloud Goldendb MEDIUM 6.5
CVE-2025-46576

There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privi…

Mitigation only
Fix from $1,600 2025-04-27