Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Support App HIGH 7.3
CVE-2024-27301

Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall install…

Fix: 2.5.1+
Fix from $1,950 2024-03-14
B2b Quick Order Form CRITICAL 9.8
CVE-2024-28391

SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privilege…

Fix: 1.3.0+
Fix from $2,300 2024-03-14
Argo Cd MEDIUM 6.4
CVE-2023-50726

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily ov…

Fix: 2.8.12 / 2.9.7+
Fix from $1,600 2024-03-13
Globalprotect MEDIUM 5.5
CVE-2024-2431

An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a us…

Fix: 5.1.12 / 6.0.4+
Fix from $1,600 2024-03-13
Globalprotect HIGH 7.0
CVE-2024-2432

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs wit…

Fix: 5.1.12 / 6.0.8+
Fix from $1,950 2024-03-13
Unclassified MEDIUM 6.5
CVE-2024-20262

A vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated, local attacker to create or…

Mitigation only
Fix from $1,600 2024-03-13
Academy Lms HIGH 8.8
CVE-2024-1505

The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to…

Fix: 1.9.20+
Fix from $1,950 2024-03-13
Unclassified HIGH 8.8
CVE-2024-1138

The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with …

Mitigation only
Fix from $1,950 2024-03-12
Windows 10 1507 HIGH 7.8
CVE-2024-26169 KEV

Windows Error Reporting Service Elevation of Privilege Vulnerability

Fix: 10.0.10240.20526 / 10.0.14393.6796+
Fix from $1,950 2024-03-12
Zitadel HIGH 7.5
CVE-2024-28197

Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the…

Fix: 2.44.3+
Fix from $1,950 2024-03-11
Android CRITICAL 9.1
CVE-2024-27207

Exported broadcast receivers allowing malicious apps to bypass broadcast protection.

No fix yet
Fix from $2,300 2024-03-11
Android HIGH 7.8
CVE-2024-27210

In policy_check of fvp.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege wit…

Mitigation only
Fix from $1,950 2024-03-11
Android HIGH 7.8
CVE-2024-27222

In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_P…

Mitigation only
Fix from $1,950 2024-03-11
Android HIGH 7.8
CVE-2024-27224

In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with…

Mitigation only
Fix from $1,950 2024-03-11
Android HIGH 7.8
CVE-2024-27233

In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege…

Mitigation only
Fix from $1,950 2024-03-11
Android HIGH 7.8
CVE-2024-22008

In config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr…

Mitigation only
Fix from $1,950 2024-03-11
Android MEDIUM 6.7
CVE-2024-25987

In pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privil…

Mitigation only
Fix from $1,600 2024-03-11
Android MEDIUM 6.4
CVE-2024-25990

In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a race condition. This could lead …

Mitigation only
Fix from $1,600 2024-03-11
Android HIGH 7.8
CVE-2024-0046

In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This c…

Patch available
Fix from $1,950 2024-03-11
Android HIGH 7.8
CVE-2024-0049

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with n…

Patch available
Fix from $1,950 2024-03-11
macOS HIGH 7.8
CVE-2024-23276

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may b…

Fix: 12.7.4 / 13.6.5+
Fix from $1,950 2024-03-08
Grafana HIGH 8.8
CVE-2024-1442

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user acc…

Fix: 9.5.7 / 10.0.12+
Fix from $1,950 2024-03-07
Unclassified HIGH 8.1
CVE-2024-22752

Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched…

Mitigation only
Fix from $1,950 2024-03-07
Blue Planet Inventory HIGH 8.0
CVE-2024-2005

In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML auth…

Fix: after 22.12
Fix from $1,950 2024-03-06
Re160v Firmware CRITICAL 9.8
CVE-2023-38944EPSS 16%

An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control a…

No fix yet
Fix from $2,300 2024-03-06
Devolutions Server HIGH 7.6
CVE-2024-1764

Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using th…

Fix: 2023.3.16.0+
Fix from $1,950 2024-03-05
Account Manager HIGH 7.5
CVE-2024-25842

An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before ve…

Fix: 9.0.0+
Fix from $1,950 2024-03-03
Product Catalog \(csv\, Excel\) Import CRITICAL 9.8
CVE-2024-25847

SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and …

Fix: after 6.5.0
Fix from $2,300 2024-03-03
Remote HIGH 7.8
CVE-2024-0819

Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged us…

Fix: 15.51.5+
Fix from $1,950 2024-02-27
Sentinel Hasp Ldk HIGH 7.8
CVE-2024-0197

A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local …

Fix: 9.16+
Fix from $1,950 2024-02-27