Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Repository Manager HIGH 7.8
CVE-2023-22576

Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged …

Fix: 3.4.3+
Fix from $1,950 2024-08-21
Unclassified HIGH 8.8
CVE-2024-43403

Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, which is bound with a Cluster…

Mitigation only
Fix from $1,950 2024-08-20
Unclassified CRITICAL 9.8
CVE-2024-33872

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privilege…

Mitigation only
Fix from $2,300 2024-08-20
Unclassified CRITICAL 9.8
CVE-2024-43311

Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a t…

Mitigation only
Fix from $2,300 2024-08-19
Unclassified CRITICAL 9.8
CVE-2024-43245

Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4.

Mitigation only
Fix from $2,300 2024-08-19
Xwiki HIGH 8.0
CVE-2024-43401

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can …

Fix: after 15.9
Fix from $1,950 2024-08-19
Microcks CRITICAL 9.8
CVE-2024-44076

In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.

Fix: 1.10.0+
Fix from $2,300 2024-08-19
Vtiger Crm HIGH 8.3
CVE-2024-42995

VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module …

Fix: after 8.1.0
Fix from $1,950 2024-08-16
Android HIGH 7.8
CVE-2024-34741

In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while…

Patch available
Fix from $1,950 2024-08-15
Android HIGH 7.8
CVE-2024-34743

In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to loca…

Patch available
Fix from $1,950 2024-08-15
Meeting Software Development Kit MEDIUM 6.7
CVE-2024-42440

Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS b…

Fix: 6.1.5+
Fix from $1,600 2024-08-14
Unclassified HIGH 8.8
CVE-2024-21807

Improper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an …

Mitigation only
Fix from $1,950 2024-08-14
Husky Products Filter Professional For Woocommerce HIGH 7.2
CVE-2024-43121

Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: from n/a through 1.3.6.1.

Fix: 1.3.6.2+
Fix from $1,950 2024-08-13
Sinec Traffic Analyzer HIGH 7.2
CVE-2024-41903

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the contain…

Fix: 2.0+
Fix from $1,950 2024-08-13
Defectdojo HIGH 8.8
CVE-2023-48171

An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

Fix: 1.5.3.1+
Fix from $1,950 2024-08-12
Collaboration HIGH 7.8
CVE-2024-27442

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the z…

Fix: 10.0.7+
Fix from $1,950 2024-08-12
Vrcx CRITICAL 9.0
CVE-2024-42366

VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-permission and cross-site script…

Fix: 2024.03.23+
Fix from $2,300 2024-08-08
Zxv10 Et301 Firmware HIGH 8.8
CVE-2024-22069

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal w…

Mitigation only
Fix from $1,950 2024-08-08
Ndoutils HIGH 7.8
CVE-2024-43199

Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.

Fix: 2.1.4+
Fix from $1,950 2024-08-07
Arcsight Intelligence CRITICAL 9.8
CVE-2024-6359

Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.

Fix: 6.4.13+
Fix from $2,300 2024-08-06
Unclassified HIGH 7.2
CVE-2024-7291

The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper …

Mitigation only
Fix from $1,950 2024-08-03
Ewon Cosy\+ Firmware HIGH 8.8
CVE-2024-33894

Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several proces…

Fix: 21.2s10 / 22.1s3+
Fix from $1,950 2024-08-02
Linkis HIGH 8.8
CVE-2024-27181

In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Link…

Fix: 1.6.0+
Fix from $1,950 2024-08-02
Biscuit Auth MEDIUM 6.4
CVE-2024-41949

biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can…

Fix: 5.0.0+
Fix from $1,600 2024-08-01
Unclassified HIGH 8.8
CVE-2024-39633

Improper Privilege Management vulnerability in IdeaBox PowerPack for Beaver Builder allows Privilege Escalation.This issue affects PowerPack for Beav…

Mitigation only
Fix from $1,950 2024-08-01
Unclassified HIGH 8.8
CVE-2024-39634

Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows Privilege Escalation.This issue affects PowerPack Pro for E…

Mitigation only
Fix from $1,950 2024-08-01
Unclassified HIGH 7.2
CVE-2024-38775

Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Feed: from n/a through 6.5.6.

Mitigation only
Fix from $1,950 2024-08-01
Unclassified CRITICAL 9.8
CVE-2024-38770

Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This …

Mitigation only
Fix from $2,300 2024-08-01
Unclassified HIGH 8.0
CVE-2023-52209

Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Re…

Mitigation only
Fix from $1,950 2024-08-01
macOS HIGH 7.8
CVE-2024-40802

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker…

Fix: 12.7.6 / 13.6.8+
Fix from $1,950 2024-07-29