Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified HIGH 8.8
CVE-2025-2238

The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to insufficient user_meta restr…

Mitigation only
Fix from $1,950 2025-04-25
Unclassified HIGH 8.8
CVE-2025-3101

The Configurator Theme Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.7. This is due to th…

Mitigation only
Fix from $1,950 2025-04-24
Unclassified HIGH 8.8
CVE-2025-3761

The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. …

Mitigation only
Fix from $1,950 2025-04-24
Uos MEDIUM 6.7
CVE-2025-1732

An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could a…

Mitigation only
Fix from $1,600 2025-04-22
Unclassified MEDIUM 6.0
CVE-2025-32955

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Versions from 0.12.0 to before 2.12.0 are vulnerable to `d…

Patch available
Fix from $1,600 2025-04-21
Unclassified CRITICAL 9.8
CVE-2025-3278

The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.4. This is due to the plugin …

Mitigation only
Fix from $2,300 2025-04-19
Unclassified HIGH 8.8
CVE-2025-28237

An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges via a crafted JSON payload.

Mitigation only
Fix from $1,950 2025-04-18
Unclassified HIGH 7.8
CVE-2025-25230

Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed m…

Mitigation only
Fix from $1,950 2025-04-16
Unclassified CRITICAL 9.1
CVE-2024-22036

A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail and gain root access to the …

Mitigation only
Fix from $2,300 2025-04-16
Unclassified MEDIUM 6.6
CVE-2023-32197

A Improper Privilege Management vulnerability in SUSE rancher in RoleTemplateobjects when external=true is set can lead to privilege escalation in sp…

Mitigation only
Fix from $1,600 2025-04-16
Xmall CRITICAL 9.8
CVE-2025-28399

An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.

No fix yet
Fix from $2,300 2025-04-15
Unclassified HIGH 8.8
CVE-2025-3418

The WPC Admin Columns plugin for WordPress is vulnerable to privilege escalation in versions 2.0.6 to 2.1.0. This is due to the plugin not properly r…

Mitigation only
Fix from $1,950 2025-04-12
macOS HIGH 7.3
CVE-2023-41076

An app may be able to elevate privileges. This issue is fixed in macOS 14. This issue was addressed by removing the vulnerable code.

Fix: 14.0+
Fix from $1,950 2025-04-11
Autoupdate HIGH 7.8
CVE-2025-29800

Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

Fix: 4.78+
Fix from $1,950 2025-04-08
Unclassified MEDIUM 6.7
CVE-2025-29999

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable files in …

Mitigation only
Fix from $1,600 2025-04-08
Ruoyi MEDIUM 6.7
CVE-2025-28400

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method

No fix yet
Fix from $1,600 2025-04-07
Ruoyi MEDIUM 6.7
CVE-2025-28401

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter

No fix yet
Fix from $1,600 2025-04-07
Woffice CRITICAL 9.8
CVE-2025-2798

The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfigur…

Fix: 5.4.22+
Fix from $2,300 2025-04-04
Unclassified HIGH 8.8
CVE-2025-3105

The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privilege escalation in all version…

Mitigation only
Fix from $1,950 2025-04-04
Trend Vision One CRITICAL 9.0
CVE-2025-31286

An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please no…

Mitigation only
Fix from $2,300 2025-04-02
Trend Vision One HIGH 7.2
CVE-2025-31284

A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create us…

Mitigation only
Fix from $1,950 2025-04-02
Trend Vision One HIGH 7.2
CVE-2025-31285

A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create…

Mitigation only
Fix from $1,950 2025-04-02
Trend Vision One HIGH 7.2
CVE-2025-31283

A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to creat…

Mitigation only
Fix from $1,950 2025-04-02
Trend Vision One HIGH 7.2
CVE-2025-31282

A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to cre…

Mitigation only
Fix from $1,950 2025-04-02
Unclassified HIGH 7.3
CVE-2025-29033

An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=" HTTP GET parameter.

Mitigation only
Fix from $1,950 2025-04-01
Unclassified HIGH 7.8
CVE-2025-22231

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can escalate their…

Mitigation only
Fix from $1,950 2025-04-01
Unclassified CRITICAL 9.8
CVE-2025-2237

The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions up to, and including, 1.6.26. …

Mitigation only
Fix from $2,300 2025-04-01
Unclassified HIGH 8.9
CVE-2025-0416

Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to C2023. The DCOM object Valmet DNA Engineering has perm…

Mitigation only
Fix from $1,950 2025-04-01
macOS HIGH 8.8
CVE-2025-24254

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. …

Fix: 13.7.5 / 14.7.5+
Fix from $1,950 2025-03-31
411 Firmware CRITICAL 9.8
CVE-2025-22937

An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.

No fix yet
Fix from $2,300 2025-03-31