Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Safenet Authentication Client HIGH 7.8
CVE-2023-5993

A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege l…

Fix: 10.8+
Fix from $1,950 2024-02-27
Safenet Authentication Client HIGH 7.8
CVE-2023-7016

A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.

Fix: 10.8+
Fix from $1,950 2024-02-27
Nagios Xi CRITICAL 9.8
CVE-2024-24402

An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

Mitigation only
Fix from $2,300 2024-02-26
Anythingllm HIGH 8.8
CVE-2024-0439

As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most manager…

Fix: 1.0.0+
Fix from $1,950 2024-02-26
Aria Operations MEDIUM 6.7
CVE-2024-22235

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can esca…

Fix: 8.16.0+
Fix from $1,600 2024-02-21
Node.js HIGH 7.8
CVE-2024-21892

On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated…

Fix: 18.19.1 / 20.11.1+
Fix from $1,950 2024-02-20
Android HIGH 7.8
CVE-2023-40106

In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could le…

Patch available
Fix from $1,950 2024-02-15
Operations Agent HIGH 7.8
CVE-2024-0622

Local privilege escalation vulnerability affects OpenText Operations Agent product versions 12.15 and 12.20-12.25 when installed on Non-Windows platf…

Fix: after 12.25
Fix from $1,950 2024-02-15
Forticlient Enterprise Management Server HIGH 7.2
CVE-2023-45581

An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site admi…

Fix: 7.0.10+
Fix from $1,950 2024-02-15
Endpoint Antivirus HIGH 7.8
CVE-2024-0353

Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permi…

Fix: 7.3.10018.0 / 7.3.12013.0+
Fix from $1,950 2024-02-15
Supportassist For Home Pcs MEDIUM 6.5
CVE-2023-25535

Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can …

Fix: 3.13.2.19+
Fix from $1,600 2024-02-14
\ HIGH 8.8
CVE-2023-52431

The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an…

Fix: 0.0.19+
Fix from $1,950 2024-02-13
Openobserve HIGH 8.8
CVE-2024-24830

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability …

Fix: 0.8.0+
Fix from $1,950 2024-02-08
Openobserve MEDIUM 6.5
CVE-2024-25106

OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulne…

Fix: 0.8.0+
Fix from $1,600 2024-02-08
N Central CRITICAL 9.8
CVE-2023-47132

An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.

Fix: 2023.7+
Fix from $2,300 2024-02-08
Secureconnector HIGH 7.0
CVE-2024-22795

Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Complia…

No fix yet
Fix from $1,950 2024-02-08
Client Security MEDIUM 6.7
CVE-2024-23764

Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and…

No fix yet
Fix from $1,600 2024-02-08
Aria Operations For Networks HIGH 7.8
CVE-2024-22237

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl…

Fix: after 6.12.0
Fix from $1,950 2024-02-06
Aria Operations For Networks HIGH 7.8
CVE-2024-22239

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl…

Fix: after 6.12.0
Fix from $1,950 2024-02-06
Display Manager HIGH 7.8
CVE-2023-32451

Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation a…

Fix: 2.1.1.21+
Fix from $1,950 2024-02-06
Command \| Monitor HIGH 7.1
CVE-2023-28049

Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploi…

Fix: 10.9.1+
Fix from $1,950 2024-02-06
Security Verify Access HIGH 7.8
CVE-2023-31005

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Pingdirectory HIGH 8.8
CVE-2023-36496

Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory…

Fix: after 9.1.0.2
Fix from $1,950 2024-02-01
Minio HIGH 8.8
CVE-2024-24747EPSS 34%

MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` ac…

Patch available
Fix from $1,950 2024-01-31
Connect Secure HIGH 8.8
CVE-2024-21888EPSS 87%

A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elev…

Mitigation only
Fix from $1,950 2024-01-31
Telerik Reporting HIGH 7.8
CVE-2024-0832

In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In …

Fix: 18.0.24.130+
Fix from $1,950 2024-01-31
Telerik Test Studio HIGH 7.8
CVE-2024-0833

In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer compon…

Fix: 2023.3.1330+
Fix from $1,950 2024-01-31
Telerik Justdecompile HIGH 7.8
CVE-2024-0219

In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. …

Fix: after 2019.1.118.0
Fix from $1,950 2024-01-31
Douro Firmware HIGH 7.8
CVE-2024-0674

Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissi…

Mitigation only
Fix from $1,950 2024-01-30
Clustered Data Ontap HIGH 7.6
CVE-2024-21985

ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authentica…

Fix: 9.9.1 / 9.10.1+
Fix from $1,950 2024-01-26