Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified MEDIUM 6.6
CVE-2023-32196

A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which i…

Mitigation only
Fix from $1,600 2024-10-16
Unclassified HIGH 7.2
CVE-2023-32194

A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject…

Mitigation only
Fix from $1,950 2024-10-16
Unclassified HIGH 7.8
CVE-2024-9002

CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and availabilit…

Mitigation only
Fix from $1,950 2024-10-11
Zxr10 1800 2s Firmware MEDIUM 6.5
CVE-2024-22068

Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality By…

Fix: 6.00.10+
Fix from $1,600 2024-10-10
Userplus CRITICAL 9.8
CVE-2024-9518

The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the …

Fix: after 2.0
Fix from $2,300 2024-10-10
Unclassified MEDIUM 6.7
CVE-2024-38818

VMware NSX contains a local privilege escalation vulnerability.  An authenticated malicious actor may exploit this vulnerability to obtain permissio…

Mitigation only
Fix from $1,600 2024-10-09
Unclassified CRITICAL 9.8
CVE-2024-3057

A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.

Mitigation only
Fix from $2,300 2024-10-08
Solvait MEDIUM 6.5
CVE-2024-45919

A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and…

No fix yet
Fix from $1,600 2024-10-07
Unclassified MEDIUM 5.9
CVE-2024-44439

An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allows a remote…

No fix yet
Fix from $1,600 2024-10-04
Nest Doorbell \(battery\) Firmware CRITICAL 9.8
CVE-2024-44097

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the se…

Fix: 1.73c+
Fix from $2,300 2024-10-02
Echo Rss Feed Post Generator CRITICAL 9.8
CVE-2024-9265

The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due …

Fix: 5.4.7+
Fix from $2,300 2024-10-01
Hit 7300 Firmware HIGH 8.4
CVE-2024-28813

An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activa…

Mitigation only
Fix from $1,950 2024-09-30
Unclassified HIGH 7.6
CVE-2024-46549

An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices …

Mitigation only
Fix from $1,950 2024-09-30
Openslides HIGH 7.5
CVE-2024-22893

OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain…

Mitigation only
Fix from $1,950 2024-09-25
Progauge Maglink Lx Console Firmware HIGH 8.8
CVE-2024-45373

Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.

Fix: after 4.17.9e
Fix from $1,950 2024-09-25
Unclassified MEDIUM 6.6
CVE-2024-44540

Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging P…

Mitigation only
Fix from $1,600 2024-09-23
Unclassified MEDIUM 6.6
CVE-2024-39342

Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Sec…

Mitigation only
Fix from $1,600 2024-09-23
Purity\/\/fa HIGH 7.2
CVE-2024-0003

A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing…

Fix: after 6.4.10
Fix from $1,950 2024-09-23
Unclassified CRITICAL 9.8
CVE-2024-34331

A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS inst…

Mitigation only
Fix from $2,300 2024-09-23
Unclassified HIGH 7.6
CVE-2024-41228

A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write a…

Mitigation only
Fix from $1,950 2024-09-23
Webo Facto CRITICAL 9.8
CVE-2024-8853

The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on t…

Fix: 1.41+
Fix from $2,300 2024-09-20
Zitadel MEDIUM 6.5
CVE-2024-46999

Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants …

Fix: 2.54.10 / 2.55.8+
Fix from $1,600 2024-09-20
Zitadel HIGH 7.5
CVE-2024-47000

Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work correctly with service accounts. D…

Fix: 2.54.10 / 2.55.8+
Fix from $1,950 2024-09-20
Logiops HIGH 7.3
CVE-2024-45752

logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus service, in…

Fix: after 0.3.4
Fix from $1,950 2024-09-19
Spicedb MEDIUM 5.3
CVE-2024-46989

spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple cav…

Fix: 1.35.3+
Fix from $1,600 2024-09-18
Unclassified CRITICAL 9.9
CVE-2024-45496

A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During…

Mitigation only
Fix from $2,300 2024-09-17
Ipados MEDIUM 5.5
CVE-2024-44147

This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized access to Local…

Fix: 18.0+
Fix from $1,600 2024-09-17
macOS HIGH 7.8
CVE-2024-40861

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to gain root privileges.

Fix: 15.0+
Fix from $1,950 2024-09-17
Music Management System HIGH 7.6
CVE-2024-42798

An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Managem…

No fix yet
Fix from $1,950 2024-09-16
Login With Phone Number HIGH 8.8
CVE-2024-6482

The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a…

Fix: 1.7.50+
Fix from $1,950 2024-09-14