Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Dryice Mycloud CRITICAL 9.1
CVE-2024-30150

HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure a…

Mitigation only
Fix from $2,300 2025-02-25
Netscaler Agent HIGH 8.8
CVE-2024-12284EPSS 13%

Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.

Fix: 13.1-56.18 / 14.1-38.53+
Fix from $1,950 2025-02-20
Unclassified HIGH 7.8
CVE-2025-0893

Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.

No fix yet
Fix from $1,950 2025-02-19
Unclassified HIGH 8.8
CVE-2024-57778

An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status code…

No fix yet
Fix from $1,950 2025-02-14
Unclassified HIGH 7.8
CVE-2025-0327

CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server m…

Mitigation only
Fix from $1,950 2025-02-13
Easyappointments CRITICAL 9.8
CVE-2024-57602

An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.

No fix yet
Fix from $2,300 2025-02-12
Unclassified HIGH 7.3
CVE-2024-21966

A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resulting in arb…

Mitigation only
Fix from $1,950 2025-02-11
Ash Authentication MEDIUM 6.5
CVE-2025-25202

Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present…

Fix: 4.4.9+
Fix from $1,600 2025-02-11
Unclassified CRITICAL 9.8
CVE-2025-0180

The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin not…

Mitigation only
Fix from $2,300 2025-02-11
Unclassified HIGH 8.8
CVE-2025-23093

The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated at…

Mitigation only
Fix from $1,950 2025-02-06
Mobile Security Framework MEDIUM 5.5
CVE-2025-24805

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security ass…

Fix: 4.3.1+
Fix from $1,600 2025-02-05
Unclassified HIGH 7.8
CVE-2024-11467

Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue…

Mitigation only
Fix from $1,950 2025-02-04
Wazuh HIGH 8.0
CVE-2024-47770

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premise…

Fix: 4.9.1+
Fix from $1,950 2025-02-03
Woocommerce Customers Manager HIGH 8.8
CVE-2024-13343

The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new…

Fix: 31.4+
Fix from $1,950 2025-02-01
Aria Operations For Logs MEDIUM 5.4
CVE-2025-22220

VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network acces…

Fix: 8.18.3+
Fix from $1,600 2025-01-30
Unclassified MEDIUM 5.5
CVE-2025-23007

A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leadi…

Mitigation only
Fix from $1,600 2025-01-30
Unclassified HIGH 7.8
CVE-2025-0834

Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate priv…

Mitigation only
Fix from $1,950 2025-01-30
Octorpki MEDIUM 5.5
CVE-2021-3978

When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided s…

Fix: 1.4.2+
Fix from $1,600 2025-01-29
Warp HIGH 7.1
CVE-2025-0651

Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges  can create a …

Fix: 2024.12.492.0+
Fix from $1,950 2025-01-22
Unclassified HIGH 8.6
CVE-2024-11218

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when buil…

Patch available
Fix from $1,950 2025-01-22
Android HIGH 7.8
CVE-2024-49742

In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a mis…

Mitigation only
Fix from $1,950 2025-01-21
Zot MEDIUM 5.3
CVE-2025-23208

zot is a production-ready vendor-neutral OCI image registry. The group data stored for users in the boltdb database (meta.db) is an append-list so gr…

Fix: 2.1.2+
Fix from $1,600 2025-01-17
Android HIGH 7.8
CVE-2018-9375

In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy…

Mitigation only
Fix from $1,950 2025-01-17
Unclassified HIGH 8.7
CVE-2024-55954

OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Adm…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified CRITICAL 9.8
CVE-2024-9636

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin …

Mitigation only
Fix from $2,300 2025-01-15
Autoupdate HIGH 7.8
CVE-2025-21360

Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

Fix: 4.76+
Fix from $1,950 2025-01-14
Windows 11 22h2 HIGH 7.5
CVE-2025-21343

Windows Web Threat Defense User Service Information Disclosure Vulnerability

Fix: 10.0.22621.4751 / 10.0.22631.4751+
Fix from $1,950 2025-01-14
Windows 10 1507 HIGH 7.8
CVE-2025-21287

Windows Installer Elevation of Privilege Vulnerability

Fix: 10.0.10240.20890 / 10.0.14393.7699+
Fix from $1,950 2025-01-14
Nwa50ax Firmware HIGH 8.8
CVE-2024-12398

An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S…

Fix: 7.10+
Fix from $1,950 2025-01-14
Virus Scanner HIGH 7.8
CVE-2024-11128

A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injec…

Fix: 3.18+
Fix from $1,950 2025-01-13