Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Complex Maintenance Repair And Overhaul MEDIUM 6.1
CVE-2024-21034

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a…

Fix: after 12.2.13
Fix from $1,600 2024-04-16
Unclassified HIGH 8.8
CVE-2024-32003

wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes …

Mitigation only
Fix from $1,950 2024-04-12
Pan Os MEDIUM 5.0
CVE-2024-3388

A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and …

Fix: 8.1.26 / 9.0.17+
Fix from $1,600 2024-04-10
Windows 10 21h2 HIGH 7.8
CVE-2024-29052

Windows Storage Elevation of Privilege Vulnerability

Fix: 10.0.19044.4291 / 10.0.19045.4291+
Fix from $1,950 2024-04-09
Windows Server 2022 23h2 HIGH 7.8
CVE-2024-28904

Microsoft Brokering File System Elevation of Privilege Vulnerability

Fix: 10.0.25398.830+
Fix from $1,950 2024-04-09
Windows Server 2022 23h2 HIGH 7.8
CVE-2024-28905

Microsoft Brokering File System Elevation of Privilege Vulnerability

Fix: 10.0.25398.830+
Fix from $1,950 2024-04-09
Defender For Iot HIGH 7.2
CVE-2024-21324

Microsoft Defender for IoT Elevation of Privilege Vulnerability

Fix: 24.1.3+
Fix from $1,950 2024-04-09
Chatrtx HIGH 8.2
CVE-2024-0082

NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file request…

Fix: 0.2.1+
Fix from $1,950 2024-04-08
Emui MEDIUM 6.2
CVE-2023-52543

Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.

No fix yet
Fix from $1,600 2024-04-08
Emui HIGH 7.5
CVE-2023-52716

Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerabil…

Mitigation only
Fix from $1,950 2024-04-07
Android HIGH 7.8
CVE-2024-29741

In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privileg…

Mitigation only
Fix from $1,950 2024-04-05
Unclassified HIGH 8.8
CVE-2024-31498

Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windows can op…

Mitigation only
Fix from $1,950 2024-04-04
Nexus Dashboard MEDIUM 6.0
CVE-2024-20282

A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to roo…

Fix: 3.1+
Fix from $1,600 2024-04-03
Poweredge R660 Firmware HIGH 7.8
CVE-2024-0172

Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local att…

Fix: 1.5.6+
Fix from $1,950 2024-04-03
Unclassified HIGH 7.1
CVE-2024-3137

Improper Privilege Management in uvdesk/community-skeleton

No fix yet
Fix from $1,950 2024-04-02
Unclassified CRITICAL 9.8
CVE-2024-29667

SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges a…

Mitigation only
Fix from $2,300 2024-03-29
Unclassified CRITICAL 9.8
CVE-2023-49232

An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to brute-force the password reset…

Mitigation only
Fix from $2,300 2024-03-29
Fineract HIGH 8.8
CVE-2024-23537

Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to versi…

Fix: 1.9.0+
Fix from $1,950 2024-03-29
Powerscale Onefs MEDIUM 6.7
CVE-2024-25961

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker coul…

Fix: 9.5.0.8 / 9.7.0.2+
Fix from $1,600 2024-03-28
Pi Hole MEDIUM 6.5
CVE-2024-28247

The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been …

Fix: 5.18+
Fix from $1,600 2024-03-27
X11ssm F Firmware HIGH 7.2
CVE-2023-40289EPSS 18%

A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privile…

Mitigation only
Fix from $1,950 2024-03-27
Unclassified HIGH 8.5
CVE-2024-1973

By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform u…

Mitigation only
Fix from $1,950 2024-03-25
Unclassified HIGH 8.1
CVE-2024-24892

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler …

Mitigation only
Fix from $1,950 2024-03-25
Identityiq HIGH 8.8
CVE-2024-2228

This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined Quick…

Fix: 8.1+
Fix from $1,950 2024-03-22
Eviden Cardos Api HIGH 7.8
CVE-2023-41099

In the Windows installer in Atos Eviden CardOS API before 5.5.5.2811, Local Privilege Escalation can occur.(from a regular user to SYSTEM).

Fix: 5.5.5.2811+
Fix from $1,950 2024-03-22
Autoexpress CRITICAL 9.8
CVE-2023-48902

An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, dele…

No fix yet
Fix from $2,300 2024-03-21
Enterprise Server MEDIUM 6.5
CVE-2024-1908

An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitH…

Fix: 3.8.16 / 3.9.11+
Fix from $1,600 2024-03-21
Unclassified HIGH 7.8
CVE-2024-2390

As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could all…

Mitigation only
Fix from $1,950 2024-03-18
Snowflake Hive Metastore Connector HIGH 7.8
CVE-2024-28851

The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addresse…

Fix: 2024-02-09+
Fix from $1,950 2024-03-15
Dgnd4000 Firmware HIGH 8.8
CVE-2023-50677

An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi compon…

Mitigation only
Fix from $1,950 2024-03-14