Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Magicos HIGH 7.5
CVE-2023-23427

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

Fix: 7.1.0.74+
Fix from $1,950 2023-12-29
Magicos HIGH 7.5
CVE-2023-23428

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

Fix: 7.2.0.102+
Fix from $1,950 2023-12-29
Magicos HIGH 7.5
CVE-2023-23429

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

Fix: 7.0.0.193+
Fix from $1,950 2023-12-29
Magichome HIGH 7.5
CVE-2023-23430

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

Fix: 7.60.10.303+
Fix from $1,950 2023-12-29
Sudo HIGH 8.8
CVE-2023-7090

A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads…

Fix: 1.8.28+
Fix from $1,950 2023-12-23
Enterprise Server MEDIUM 5.5
CVE-2023-6804

Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this, a workflow must ha…

Fix: 3.8.12 / 3.9.7+
Fix from $1,600 2023-12-21
Enterprise Server HIGH 8.8
CVE-2023-46647

Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management console with an edito…

Fix: 3.8.12 / 3.9.6+
Fix from $1,950 2023-12-21
Thegreenbow Vpn Client CRITICAL 9.8
CVE-2023-47267

An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client …

Fix: 6.52.006 / 6.87.108+
Fix from $2,300 2023-12-19
Privilege Management For Windows HIGH 7.8
CVE-2020-12615

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding the Add Admin token to a process, and specifying tha…

Fix: 5.6+
Fix from $1,950 2023-12-12
Postgres Advanced Server HIGH 8.8
CVE-2023-41119

An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9…

Fix: 11.21.32 / 12.16.20+
Fix from $1,950 2023-12-12
Android MEDIUM 6.7
CVE-2023-48406

there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic error in the code. This could lead to local escalat…

Mitigation only
Fix from $1,600 2023-12-08
Huddlycameraservices HIGH 7.8
CVE-2023-45253

An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, allows attackers to manipulate files and esca…

Fix: 8.0.7+
Fix from $1,950 2023-12-01
Moveit Transfer HIGH 7.2
CVE-2023-6218

In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associate…

Fix: 2022.0.9 / 2022.1.10+
Fix from $1,950 2023-11-29
Zld MEDIUM 5.5
CVE-2023-5797

An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series …

Fix: 6.70 / 6.80+
Fix from $1,600 2023-11-28
Zld MEDIUM 5.5
CVE-2023-5960

An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series…

Fix: after 5.37
Fix from $1,600 2023-11-28
Zld MEDIUM 5.5
CVE-2023-5650

An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware vers…

Fix: after 5.37
Fix from $1,600 2023-11-28
Zld MEDIUM 5.5
CVE-2023-37925

An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series …

Fix: 6.70 / 6.80+
Fix from $1,600 2023-11-28
Pandora Fms HIGH 7.5
CVE-2023-41806

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability causes that a bad privilege assignm…

Fix: after 773
Fix from $1,950 2023-11-23
Pandora Fms HIGH 8.8
CVE-2023-41807

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows a user to escalate permissio…

Fix: after 773
Fix from $1,950 2023-11-23
Pandora Fms HIGH 7.5
CVE-2023-41808

Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation. This vulnerability allows an unauthorised user to esca…

Fix: after 773
Fix from $1,950 2023-11-23
Elasticsearch HIGH 8.8
CVE-2021-37937

An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is poss…

Fix: after 7.14.0
Fix from $1,950 2023-11-22
Apm Java Agent HIGH 7.8
CVE-2021-37942

A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application ru…

Fix: after 1.27.0
Fix from $1,950 2023-11-22
Appdynamics HIGH 7.8
CVE-2023-20274

A vulnerability in the installer script of Cisco AppDynamics PHP Agent could allow an authenticated, local attacker to elevate privileges on an affec…

Mitigation only
Fix from $1,950 2023-11-21
Getsusp HIGH 7.8
CVE-2023-6119

An Improper Privilege Management vulnerability in Trellix GetSusp prior to version 5.0.0.27 allows a local, low privilege attacker to gain access to …

Fix: 5.0.0.27+
Fix from $1,950 2023-11-16
Repository Manager HIGH 7.8
CVE-2023-44292

Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attack…

Fix: 3.4.4+
Fix from $1,950 2023-11-16
Repository Manager HIGH 7.8
CVE-2023-44282

Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attack…

Fix: after 3.4.3
Fix from $1,950 2023-11-16
Endpoint Manager Mobile CRITICAL 9.8
CVE-2023-39335

A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate …

Fix: 11.9.0 / 11.10.0.4+
Fix from $2,300 2023-11-15
Data Center Manager CRITICAL 9.8
CVE-2023-31273

Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalation of priv…

Fix: 5.2+
Fix from $2,300 2023-11-14
Aptio V Uefi Firmware Integrator Tools HIGH 7.8
CVE-2023-28737

Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of …

Mitigation only
Fix from $1,950 2023-11-14
Ryzen 3 5100 Firmware HIGH 7.8
CVE-2023-20563

Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

No fix yet
Fix from $1,950 2023-11-14