Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified HIGH 7.8
CVE-2024-53706

A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to elevate privileges to `root` a…

Mitigation only
Fix from $1,950 2025-01-09
Emui HIGH 7.5
CVE-2024-56447

Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service…

No fix yet
Fix from $1,950 2025-01-08
Unclassified MEDIUM 6.4
CVE-2025-22621

In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability …

Mitigation only
Fix from $1,600 2025-01-07
Apex One HIGH 7.8
CVE-2024-55632

A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. …

Fix: 14.0.14203 / 2019.13140+
Fix from $1,950 2024-12-31
Apex One HIGH 7.8
CVE-2024-55631

An engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Plea…

Fix: 14.0.14203 / 2019.13140+
Fix from $1,950 2024-12-31
Fusioncompute HIGH 7.8
CVE-2020-9222

There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be des…

Mitigation only
Fix from $1,950 2024-12-27
Mate 20 Pro Firmware HIGH 7.8
CVE-2020-9080

There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specific input t…

Fix: 10.0.0.125+
Fix from $1,950 2024-12-27
Vaultwarden HIGH 7.5
CVE-2024-56335

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable…

Fix: 1.32.7+
Fix from $1,950 2024-12-20
Unclassified HIGH 7.8
CVE-2024-12786

A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNe…

Mitigation only
Fix from $1,950 2024-12-19
Forticlient HIGH 7.8
CVE-2020-15934

An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow …

Fix: 6.2.8+
Fix from $1,950 2024-12-19
Unclassified HIGH 8.8
CVE-2024-38499

CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to…

Mitigation only
Fix from $1,950 2024-12-17
Unclassified CRITICAL 9.3
CVE-2024-55949

MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM imp…

Patch available
Fix from $2,300 2024-12-16
Frontend Admin HIGH 8.1
CVE-2024-11721

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5. This is due…

Fix: 3.25.1+
Fix from $1,950 2024-12-14
Partner Center CRITICAL 9.8
CVE-2024-49035 KEV

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2024-11-26
Unclassified HIGH 7.8
CVE-2024-52336

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users…

Mitigation only
Fix from $1,950 2024-11-26
Aria Operations HIGH 7.8
CVE-2024-38830

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this v…

Fix: 8.18.2+
Fix from $1,950 2024-11-26
Wordpress Gym Management System HIGH 8.8
CVE-2024-9941

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gm…

Fix: 67.2.0+
Fix from $1,950 2024-11-23
Kafka MEDIUM 6.5
CVE-2024-31141

Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accep…

Fix: after 3.6.2
Fix from $1,600 2024-11-19
Unclassified MEDIUM 5.4
CVE-2020-26063

A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authoriza…

Mitigation only
Fix from $1,600 2024-11-18
Unclassified MEDIUM 6.5
CVE-2024-52926

Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

No fix yet
Fix from $1,600 2024-11-18
Unclassified HIGH 8.8
CVE-2024-9192

The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on …

Mitigation only
Fix from $1,950 2024-11-16
Session Recording HIGH 8.0
CVE-2024-8068 KEV

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Activ…

Fix: 2407+
Fix from $1,950 2024-11-12
Smartfabric Os10 HIGH 7.8
CVE-2024-49558

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerability. A low p…

Fix: 10.5.4.13 / 10.5.5.12+
Fix from $1,950 2024-11-12
Manageengine Admanager Plus HIGH 8.8
CVE-2024-24409

Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

Mitigation only
Fix from $1,950 2024-11-08
Unclassified HIGH 8.5
CVE-2024-8424

Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file del…

Mitigation only
Fix from $1,950 2024-11-08
Enterprise Server MEDIUM 6.5
CVE-2024-8810

A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator.…

Fix: 3.10.17 / 3.11.15+
Fix from $1,600 2024-11-07
Manageengine Endpoint Central HIGH 7.8
CVE-2024-10203

Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent …

Fix: after 11.3.2428.09
Fix from $1,950 2024-11-07
Harmonyos MEDIUM 5.5
CVE-2024-51521

Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availabi…

No fix yet
Fix from $1,600 2024-11-05
Secure Firewall Management Center HIGH 7.2
CVE-2024-20374

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center…

Mitigation only
Fix from $1,950 2024-10-23
Deep Security Agent HIGH 7.8
CVE-2024-48903

An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affected instal…

Fix: 20.0.1+
Fix from $1,950 2024-10-22