Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Merge Efilm Workstation HIGH 7.8
CVE-2024-23620

An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated attacker can exploit this vul…

Fix: after 4.2
Fix from $1,950 2024-01-26
Visitor Management System CRITICAL 9.8
CVE-2024-22922

An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page…

Mitigation only
Fix from $2,300 2024-01-25
Coign HIGH 8.8
CVE-2023-43317

An issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList parameter in Session Storage compone…

No fix yet
Fix from $1,950 2024-01-24
Apex One HIGH 7.8
CVE-2023-52093

An exposed dangerous function vulnerability in the Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected install…

Fix: 14.0.12849+
Fix from $1,950 2024-01-23
Deep Security HIGH 7.8
CVE-2023-52337

An improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could all…

Mitigation only
Fix from $1,950 2024-01-23
Apex One HIGH 7.8
CVE-2023-47201

A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on a…

Fix: 14.0.12737+
Fix from $1,950 2024-01-23
Firefox HIGH 8.8
CVE-2024-0751

A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunde…

Fix: 115.7 / 122.0+
Fix from $1,950 2024-01-23
Harmonyos HIGH 7.5
CVE-2023-52105

The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,950 2024-01-16
Emui HIGH 7.5
CVE-2023-52116

Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exception…

Mitigation only
Fix from $1,950 2024-01-16
Emui HIGH 7.5
CVE-2023-52107

Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confiden…

Mitigation only
Fix from $1,950 2024-01-16
Emui HIGH 7.5
CVE-2023-52114

Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity.

No fix yet
Fix from $1,950 2024-01-16
Checkmk HIGH 7.8
CVE-2023-6735

Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

Fix: after 2.0.0
Fix from $1,950 2024-01-12
Checkmk HIGH 7.8
CVE-2023-6740

Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges

Fix: after 2.0.0
Fix from $1,950 2024-01-12
Azure Ipam CRITICAL 9.8
CVE-2024-21638

Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP …

Fix: 3.0.0+
Fix from $2,300 2024-01-10
macOS MEDIUM 5.5
CVE-2022-32931

This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to access pr…

Fix: 13.0+
Fix from $1,600 2024-01-10
Fortiproxy HIGH 8.8
CVE-2023-44250

An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy H…

Mitigation only
Fix from $1,950 2024-01-10
Db2 HIGH 7.8
CVE-2023-47145

IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using…

Fix: 10.5.0.11 / 11.1.4.7+
Fix from $1,950 2024-01-07
Redmagic 8 Pro Firmware MEDIUM 5.5
CVE-2023-41784

Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro

No fix yet
Fix from $1,600 2024-01-04
Craft Cms HIGH 8.8
CVE-2024-21622

Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x…

Fix: 3.9.6+
Fix from $1,950 2024-01-03
Kruise MEDIUM 6.5
CVE-2023-30617

Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1, 1.4.1, and 1.5…

Fix: 1.3.1 / 1.4.1+
Fix from $1,600 2024-01-03
Gl Mt1300 Firmware CRITICAL 9.8
CVE-2023-50921

An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. T…

Mitigation only
Fix from $2,300 2024-01-03
Zxcloud Irai HIGH 7.8
CVE-2023-41776

There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to es…

Fix: 7.23.32+
Fix from $1,950 2024-01-03
Pixel Watch Firmware HIGH 7.8
CVE-2023-48418

In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default…

No fix yet
Fix from $1,950 2024-01-02
Nest Audio Firmware CRITICAL 9.8
CVE-2023-48419

An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 

Fix: 2.58+
Fix from $2,300 2024-01-02
Wrangler HIGH 8.0
CVE-2023-7080

The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspe…

Fix: 2.20.2 / 3.19.0+
Fix from $1,950 2023-12-29
Magic Ui MEDIUM 5.5
CVE-2023-51433

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.

Fix: 6.1.0.212+
Fix from $1,600 2023-12-29
Magic Ui HIGH 7.1
CVE-2023-51435

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.

Fix: 6.1.0.212+
Fix from $1,950 2023-12-29
Magic Os MEDIUM 5.5
CVE-2023-51429

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.

Fix: 7.0.0.156+
Fix from $1,600 2023-12-29
Magic Ui MEDIUM 5.5
CVE-2023-51430

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.

Fix: 6.1.0.212+
Fix from $1,600 2023-12-29
Lge An00 Firmware MEDIUM 5.5
CVE-2023-23438

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions

Fix: 6.0.0.188+
Fix from $1,600 2023-12-29