Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Ryzen 3 5100 Firmware HIGH 7.8
CVE-2023-20565

Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

Mitigation only
Fix from $1,950 2023-11-14
Nuc Pro Software Suite HIGH 7.8
CVE-2022-41700

Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user t…

Fix: 2.0.0.9+
Fix from $1,950 2023-11-14
Datahub HIGH 8.0
CVE-2023-47629

DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as …

Fix: 0.12.1+
Fix from $1,950 2023-11-14
Facial Love Cloud Platform CRITICAL 9.8
CVE-2023-6099

A vulnerability classified as critical has been found in Shenzhen Youkate Industrial Facial Love Cloud Payment System up to 1.0.55.0.0.1. This affect…

Fix: after 1.0.55.0.0.1
Fix from $2,300 2023-11-13
Bgs5 Firmware HIGH 7.8
CVE-2023-47611

A CWE-269: Improper Privilege Management vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cint…

Mitigation only
Fix from $1,950 2023-11-10
Edge Chromium HIGH 7.1
CVE-2023-36024

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 118.0.2088.102 / 119.0.2151.58+
Fix from $1,950 2023-11-10
Moodle MEDIUM 5.3
CVE-2023-5549

Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not hav…

Fix: 3.9.24 / 3.11.17+
Fix from $1,600 2023-11-09
Appsanywhere Client MEDIUM 6.7
CVE-2023-41138

The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process.

Mitigation only
Fix from $1,600 2023-11-09
Harmonyos HIGH 7.5
CVE-2023-46758

Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exception…

No fix yet
Fix from $1,950 2023-11-08
Harmonyos MEDIUM 5.3
CVE-2023-46756

Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows.

Mitigation only
Fix from $1,600 2023-11-08
Emui HIGH 7.5
CVE-2023-46771

Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2023-11-08
FreeBSD HIGH 7.5
CVE-2023-5978

In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updat…

Fix: 13.2+
Fix from $1,950 2023-11-08
Gs1900 48hpv2 Firmware MEDIUM 5.5
CVE-2023-35140

The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local use…

Fix: after 2.70
Fix from $1,600 2023-11-07
Macvim HIGH 7.8
CVE-2023-41036

Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC) mechanism which could lead …

Fix: 178+
Fix from $1,950 2023-11-07
Cics Tx HIGH 7.5
CVE-2023-43018

IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which cr…

Patch available
Fix from $1,950 2023-11-03
Openshift Container Platform HIGH 7.2
CVE-2023-5408

A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modif…

Patch available
Fix from $1,950 2023-11-02
Secure Firewall Management Center CRITICAL 9.9
CVE-2023-20048EPSS 16%

A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to ex…

Fix: after 7.3.1.1
Fix from $2,300 2023-11-01
Nessus HIGH 7.3
CVE-2023-5847

Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Wind…

Fix: 10.4.3 / 10.6.2+
Fix from $1,950 2023-11-01
Image Assistant HIGH 7.8
CVE-2023-5739

Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.

Fix: 2.4.0.0 / 5.1.8+
Fix from $1,950 2023-10-31
Openvpn Client HIGH 7.8
CVE-2023-47101

The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalation during installation or rep…

Fix: 2.0.40+
Fix from $1,950 2023-10-30
Android HIGH 7.8
CVE-2023-21374

In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to local escalation of privilege …

Mitigation only
Fix from $1,950 2023-10-30
Android MEDIUM 5.5
CVE-2023-21376

In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no…

Fix: 14.0+
Fix from $1,600 2023-10-30
Android HIGH 7.8
CVE-2023-21396

In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privileg…

Fix: 14.0+
Fix from $1,950 2023-10-30
Android HIGH 7.8
CVE-2023-21397

In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of privilege wi…

Fix: 14.0+
Fix from $1,950 2023-10-30
Android HIGH 7.8
CVE-2023-21343

In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege w…

Fix: 14.0+
Fix from $1,950 2023-10-30
I HIGH 7.8
CVE-2023-40685

Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with com…

Patch available
Fix from $1,950 2023-10-29
I HIGH 7.8
CVE-2023-40686

Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with com…

Patch available
Fix from $1,950 2023-10-29
System Update Plugin HIGH 7.8
CVE-2022-3701

A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local att…

Fix: 1.3.1.2 / 2.0.0.213+
Fix from $1,950 2023-10-27
Directory Services Connector HIGH 7.8
CVE-2023-44219

A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local lo…

Fix: 4.1.22+
Fix from $1,950 2023-10-27
Tools HIGH 7.8
CVE-2023-34057

VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate pri…

Fix: 12.1.1+
Fix from $1,950 2023-10-27