Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Android HIGH 7.8
CVE-2024-31325

In multiple locations, there is a possible way to reveal images across users data due to a logic error in the code. This could lead to local escalati…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-23711

In DevmemXIntUnreserveRange of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to …

Mitigation only
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31311

In increment_annotation_count of stats_event.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escal…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2024-31313

In availableToWriteBytes of MessageQueueBase.h, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2023-21113

In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit…

Patch available
Fix from $1,950 2024-07-09
Android HIGH 7.8
CVE-2023-21114

In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no addit…

Patch available
Fix from $1,950 2024-07-09
Defender For Iot CRITICAL 9.9
CVE-2024-38089

Microsoft Defender for IoT Elevation of Privilege Vulnerability

Fix: 24.1.4+
Fix from $2,300 2024-07-09
Book Your Travel HIGH 8.8
CVE-2024-37952

Improper Privilege Management vulnerability in themeenergy BookYourTravel allows Privilege Escalation.This issue affects BookYourTravel: from n/a thr…

Fix: after 8.18.17
Fix from $1,950 2024-07-09
Zephyr Project Manager HIGH 8.8
CVE-2024-37484

Improper Privilege Management vulnerability in Dylan James Zephyr Project Manager allows Privilege Escalation.This issue affects Zephyr Project Manag…

Fix: 3.3.99+
Fix from $1,950 2024-07-09
Ultimate Addons For Elementor HIGH 8.8
CVE-2024-37455

Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate…

Fix: 1.36.32+
Fix from $1,950 2024-07-09
Eskooly HIGH 8.8
CVE-2024-27711

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process fu…

Fix: after 3.0
Fix from $1,950 2024-07-05
Eskooly CRITICAL 9.8
CVE-2024-27710

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authentication me…

Fix: after 3.0
Fix from $2,300 2024-07-05
Unclassified MEDIUM 6.8
CVE-2024-37726

Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to escalate privileges via the …

Mitigation only
Fix from $1,600 2024-07-03
Unclassified HIGH 7.5
CVE-2024-39206

An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to engin…

Mitigation only
Fix from $1,950 2024-07-02
Windriver HIGH 7.8
CVE-2024-25086

Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.

Fix: 12.2.0+
Fix from $1,950 2024-07-02
Windriver HIGH 7.8
CVE-2024-25088

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.

Fix: 12.5.1+
Fix from $1,950 2024-07-02
Windriver HIGH 7.8
CVE-2024-26314

Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.

Fix: 16.2.0+
Fix from $1,950 2024-07-02
Windriver HIGH 7.8
CVE-2024-22106

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Deni…

Fix: 12.5.1+
Fix from $1,950 2024-07-02
Windriver HIGH 7.8
CVE-2023-51776

Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.

Fix: 12.1.0+
Fix from $1,950 2024-07-02
Powerscale Onefs MEDIUM 6.7
CVE-2024-37126

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could…

Fix: 9.7.1.0+
Fix from $1,600 2024-07-02
Powerscale Onefs MEDIUM 6.7
CVE-2024-37133

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could…

Fix: 9.4.0.18 / 9.5.1.0+
Fix from $1,600 2024-07-02
Powerscale Onefs MEDIUM 6.7
CVE-2024-32854

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could …

Fix: 9.5.1.0 / 9.7.1.0+
Fix from $1,600 2024-07-02
Unclassified HIGH 7.8
CVE-2024-4395

The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation.

Mitigation only
Fix from $1,950 2024-06-27
Whatsup Gold HIGH 8.4
CVE-2024-5009EPSS 15%

In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword …

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Wishlist Member X HIGH 8.8
CVE-2024-37107

Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X…

Fix: after 3.26.7
Fix from $1,950 2024-06-24
Snapd HIGH 8.8
CVE-2020-27352

When generating the systemd service units for the docker snap (and other similar snaps), snapd does not specify Delegate=yes - as a result systemd wi…

Fix: 2.48.3+
Fix from $1,950 2024-06-21
Parallels Desktop CRITICAL 10.0
CVE-2024-6240

Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. An attacker could add maliciou…

Fix: 19.3.0+
Fix from $2,300 2024-06-21
Unclassified HIGH 7.3
CVE-2024-2003

Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.

Mitigation only
Fix from $1,950 2024-06-21
Depicter MEDIUM 6.5
CVE-2024-4390

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0…

Fix: 3.1.0+
Fix from $1,600 2024-06-20
Jlink Ax1800 Firmware CRITICAL 9.8
CVE-2023-37058

Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to escalate privileges via a craf…

Mitigation only
Fix from $2,300 2024-06-17