Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Satech Bcu Firmware HIGH 8.8
CVE-2025-2858

Privilege escalation vulnerability in the saTECH BCU firmware version 2.1.3. An attacker with access to the CLI of the device could make use of the n…

Mitigation only
Fix from $1,950 2025-03-28
Apex One HIGH 7.8
CVE-2024-58104

A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security a…

Fix: 14.0.14203 / 2019.13140+
Fix from $1,950 2025-03-25
Accountsservice MEDIUM 5.5
CVE-2022-1804

accountsservice no longer drops permissions when writting .pam_environment

Fix: 22.07.5-2ubuntu1.3+
Fix from $1,600 2025-03-25
Kubeslice HIGH 7.4
CVE-2024-53350

Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escalation of privileges.

Fix: after 1.3.1
Fix from $1,950 2025-03-21
Kuadrant HIGH 7.4
CVE-2024-53349

Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the s…

Fix: after 0.11.3
Fix from $1,950 2025-03-21
Xwiki HIGH 7.5
CVE-2025-29924

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private informatio…

Fix: 15.10.14 / 16.4.6+
Fix from $1,950 2025-03-19
Moveit Transfer HIGH 8.8
CVE-2025-2324

Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escala…

Fix: 2023.1.12 / 2024.0.8+
Fix from $1,950 2025-03-19
Smartfabric Os10 MEDIUM 5.5
CVE-2024-48828

Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Management vulnerability. A low p…

Fix: 10.5.4.14 / 10.5.5.13+
Fix from $1,600 2025-03-17
Openpanel MEDIUM 5.5
CVE-2025-25872

An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function

No fix yet
Fix from $1,600 2025-03-14
Realteo CRITICAL 9.8
CVE-2025-2232

The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authentication bypass in all versions…

Fix: 1.2.9+
Fix from $2,300 2025-03-14
Unclassified HIGH 8.8
CVE-2024-13376

The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capabili…

Mitigation only
Fix from $1,950 2025-03-14
Soundcloud MEDIUM 6.7
CVE-2024-57062

An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the session handl…

Mitigation only
Fix from $1,600 2025-03-13
Azure Agent MEDIUM 6.7
CVE-2025-21199

Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.

Fix: 2.0.9940.0 / 9.30+
Fix from $1,600 2025-03-11
Goldendb HIGH 7.5
CVE-2025-26705

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Fix: 6.1.03.06+
Fix from $1,950 2025-03-11
Goldendb MEDIUM 5.3
CVE-2025-26706

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.07.

Fix: after 6.1.03.07
Fix from $1,600 2025-03-11
Unclassified MEDIUM 5.3
CVE-2025-26707

Improper Privilege Management vulnerability in ZTE GoldenDB allows Privilege Escalation.This issue affects GoldenDB: from 6.1.03 through 6.1.03.05.

Mitigation only
Fix from $1,600 2025-03-11
Ipados MEDIUM 5.5
CVE-2024-54560

A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A malicious app…

Fix: 11.0 / 15.0+
Fix from $1,600 2025-03-10
Javo Core CRITICAL 9.8
CVE-2025-0177

The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin a…

Fix: 3.0.0.266+
Fix from $2,300 2025-03-08
Post Meta Data Manager HIGH 7.2
CVE-2024-13835

The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, and including, 1.4.4. This is …

Fix: after 1.4.3
Fix from $1,950 2025-03-08
Chrome Os MEDIUM 6.8
CVE-2025-1121

Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access…

Mitigation only
Fix from $1,600 2025-03-07
Unclassified CRITICAL 9.8
CVE-2024-11951

The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.0. This is due to the p…

Mitigation only
Fix from $2,300 2025-03-05
Unclassified CRITICAL 9.8
CVE-2024-12281

The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is due to the plugin allowing u…

Mitigation only
Fix from $2,300 2025-03-05
Vasion Print HIGH 8.8
CVE-2025-27639

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Privilege Escalation V-2024-015.

Fix: 20.0.2614 / 22.0.1002+
Fix from $1,950 2025-03-05
Vasion Print HIGH 7.8
CVE-2025-27644

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Local Privilege Escalation V-2024-007.

Fix: 20.0.2368 / 22.0.933+
Fix from $1,950 2025-03-05
Unclassified HIGH 8.6
CVE-2025-1424

A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if they gain physical access to the…

Mitigation only
Fix from $1,950 2025-03-04
Streampipes MEDIUM 6.5
CVE-2024-24778

Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This i…

Fix: 0.97.0+
Fix from $1,600 2025-03-03
Dhvc Form CRITICAL 9.8
CVE-2024-8420

The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. This is due to the plugin allow…

Fix: 2.4.8+
Fix from $2,300 2025-02-28
Nios CRITICAL 9.8
CVE-2024-36046

Infoblox NIOS through 8.6.4 executes with more privileges than required.

Fix: after 8.6.4
Fix from $2,300 2025-02-27
Bricks HIGH 8.8
CVE-2024-2297

The Bricks theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.6.1. This is due to insufficient valid…

Fix: 1.9.7+
Fix from $1,950 2025-02-27
Unclassified HIGH 8.8
CVE-2025-1295

The Templines Elementor Helper Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.7. This is due…

Mitigation only
Fix from $1,950 2025-02-27