Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified CRITICAL 9.8
CVE-2024-33374

Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authe…

Mitigation only
Fix from $2,300 2024-06-14
Emui MEDIUM 5.5
CVE-2024-36499

Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confide…

No fix yet
Fix from $1,600 2024-06-14
Emui MEDIUM 5.5
CVE-2024-36500

Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,600 2024-06-14
Android MEDIUM 6.1
CVE-2024-32918

Permission Bypass allowing attackers to disable HDCP 2.2 encryption by not completing the HDCP Key Exchange initialization steps

Mitigation only
Fix from $1,600 2024-06-13
Android HIGH 7.0
CVE-2024-32899

In gpu_pm_power_off_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a race condition. This could lead to l…

Mitigation only
Fix from $1,950 2024-06-13
Android HIGH 7.8
CVE-2024-32906

In AcvpOnMessage of avcp.cpp, there is a possible EOP due to uninitialized data. This could lead to local escalation of privilege with no additional …

Mitigation only
Fix from $1,950 2024-06-13
Android HIGH 7.8
CVE-2024-29784

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of…

Mitigation only
Fix from $1,950 2024-06-13
Unclassified HIGH 8.8
CVE-2024-36586

An issue in AdGuardHome v0.93 to latest allows unprivileged attackers to escalate privileges via overwriting the AdGuardHome binary.

Mitigation only
Fix from $1,950 2024-06-13
Gb28181 HIGH 8.8
CVE-2024-37665

An access control issue in Wvp GB28181 Pro 2.0 allows authenticated attackers to escalate privileges to Administrator via a crafted POST request.

No fix yet
Fix from $1,950 2024-06-12
Cortex Xdr Agent HIGH 7.0
CVE-2024-5907

A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with…

Fix: 7.9.102 / 8.2.3+
Fix from $1,950 2024-06-12
Cortex Xdr Agent MEDIUM 5.5
CVE-2024-5909

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a low privileged local Windows user to dis…

Fix: 7.9.102 / 8.1.2+
Fix from $1,600 2024-06-12
Security Center MEDIUM 6.3
CVE-2024-5759

An improper privilege management vulnerability exists in Tenable Security Center where an authenticated, remote attacker could view unauthorized obje…

Fix: after 6.3.0
Fix from $1,600 2024-06-12
Unclassified MEDIUM 5.9
CVE-2024-33500

A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (V10.6) (Al…

Mitigation only
Fix from $1,600 2024-06-11
Elite Slice Firmware MEDIUM 6.8
CVE-2022-37019

Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execut…

Fix: 00.02.64 / 01.62+
Fix from $1,600 2024-06-10
Maximum Security 2022 HIGH 7.8
CVE-2024-32849

Trend Micro Security 17.x (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delet…

Fix: 17.7+
Fix from $1,950 2024-06-10
Ipados HIGH 7.8
CVE-2024-27811

The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10…

Fix: 1.2 / 10.5+
Fix from $1,950 2024-06-10
Unclassified HIGH 7.8
CVE-2024-34332

An issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a crafted buffer sent to the Ker…

Mitigation only
Fix from $1,950 2024-06-10
Unclassified MEDIUM 6.8
CVE-2024-37364

Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensitive info…

Mitigation only
Fix from $1,600 2024-06-06
Armember HIGH 8.8
CVE-2023-47837

Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through …

Fix: 4.0.11+
Fix from $1,950 2024-06-04
Nas326 Firmware MEDIUM 6.5
CVE-2024-29976EPSS 9%

** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyxel NAS326 firmware versions b…

Fix: 5.21+
Fix from $1,600 2024-06-04
Nas326 Firmware MEDIUM 6.7
CVE-2024-29975

** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions befor…

Fix: 5.21+
Fix from $1,600 2024-06-04
Secure Access Client HIGH 7.3
CVE-2023-46810

A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as ro…

Fix: 22.7+
Fix from $1,950 2024-05-31
Astrotalks HIGH 8.8
CVE-2024-5525

Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a local user to access the applicat…

Mitigation only
Fix from $1,950 2024-05-31
Zkbio Cvsecurity HIGH 8.1
CVE-2024-35430

In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the app…

No fix yet
Fix from $1,950 2024-05-30
Pe6208 Firmware CRITICAL 9.8
CVE-2023-43845

Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to change the credentials after fir…

Fix: 2.4.239+
Fix from $2,300 2024-05-28
Unclassified MEDIUM 5.4
CVE-2024-36056

Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily map physical memory via IOCTL 0x9c406490 (for Io…

Mitigation only
Fix from $1,600 2024-05-26
Unclassified HIGH 7.4
CVE-2024-34454

Nintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA, because there is a secondary…

Mitigation only
Fix from $1,950 2024-05-26
I HIGH 7.8
CVE-2024-27264

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malici…

Mitigation only
Fix from $1,950 2024-05-22
Unclassified HIGH 8.8
CVE-2024-36077

Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can el…

Mitigation only
Fix from $1,950 2024-05-22
Unclassified HIGH 8.8
CVE-2024-33223

An issue in the component IOMap64.sys of ASUSTeK Computer Inc ASUS GPU TweakII v1.4.5.2 allows attackers to escalate privileges and execute arbitrary…

Mitigation only
Fix from $1,950 2024-05-22