Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Nessus Network Monitor HIGH 8.8
CVE-2023-5622

Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by …

Fix: 6.3.0+
Fix from $1,950 2023-10-26
Analog Fm Transmitter Exc5000gx Firmware HIGH 8.8
CVE-2023-41966

The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to se…

No fix yet
Fix from $1,950 2023-10-26
Print And Scan Doctor HIGH 7.8
CVE-2023-5671

HP Print and Scan Doctor for Windows may potentially be vulnerable to escalation of privilege. HP is releasing software updates to mitigate the poten…

Mitigation only
Fix from $1,950 2023-10-25
Thinkagile Hx5530 Firmware HIGH 8.8
CVE-2023-4607

An authenticated XCC user can change permissions for any user through a crafted API command.

Mitigation only
Fix from $1,950 2023-10-25
Clearpass Policy Manager HIGH 7.8
CVE-2023-43506

A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a h…

Fix: 6.9.13 / 6.10.8+
Fix from $1,950 2023-10-25
Tokueimaru Waiting HIGH 8.2
CVE-2023-39732

The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast mes…

No fix yet
Fix from $1,950 2023-10-25
Tonton Tei HIGH 8.2
CVE-2023-39733

The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

No fix yet
Fix from $1,950 2023-10-25
Trackdiner10\/10 Mc HIGH 8.2
CVE-2023-39734

The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send cr…

No fix yet
Fix from $1,950 2023-10-25
Onigiriya Musubee HIGH 8.2
CVE-2023-39740

The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast mess…

No fix yet
Fix from $1,950 2023-10-25
Client Connector MEDIUM 5.5
CVE-2021-26734

Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversar…

Fix: 3.4.0.124+
Fix from $1,600 2023-10-23
Fusion HIGH 7.8
CVE-2023-34045

VMware Fusion(13.x prior to 13.5) contains a local privilege escalation vulnerability that occurs during installation for the first time (the user n…

Fix: 13.5+
Fix from $1,950 2023-10-20
Please HIGH 7.8
CVE-2023-46277

please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disable…

Fix: after 0.5.4
Fix from $1,950 2023-10-20
Easyinstall HIGH 7.8
CVE-2023-27793

An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges via weak encoding of sensitive informa…

No fix yet
Fix from $1,950 2023-10-19
Easyinstall HIGH 7.8
CVE-2023-27795

An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key.

No fix yet
Fix from $1,950 2023-10-19
Qumu HIGH 7.8
CVE-2023-45883

A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair …

Fix: 2.0.63+
Fix from $1,950 2023-10-19
Sonicos HIGH 8.8
CVE-2023-41715

SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside…

Fix: 6.5.4.4-44v-21-2340 / 6.5.4.13-105n+
Fix from $1,950 2023-10-17
Vm Virtualbox HIGH 8.2
CVE-2023-22099

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.…

Fix: 7.0.12+
Fix from $1,950 2023-10-17
Radeon Software HIGH 7.8
CVE-2023-20598

An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control…

Fix: 23.q4 / 23.9.2+
Fix from $1,950 2023-10-17
Exos HIGH 8.8
CVE-2023-43120

An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privil…

Fix: 22.7 / 31.7.1+
Fix from $1,950 2023-10-16
Grafana HIGH 7.2
CVE-2023-4822

Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allo…

Fix: 9.4.16 / 9.5.11+
Fix from $1,950 2023-10-16
Dir 820l Firmware CRITICAL 9.8
CVE-2023-44809

D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.

No fix yet
Fix from $2,300 2023-10-16
Hardware Management Console HIGH 7.8
CVE-2023-38280

IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricte…

Patch available
Fix from $1,950 2023-10-16
I HIGH 7.8
CVE-2023-40377

Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerability. A malicious actor with …

Patch available
Fix from $1,950 2023-10-16
I HIGH 7.8
CVE-2023-40378

IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating…

Patch available
Fix from $1,950 2023-10-15
Snapcenter HIGH 7.8
CVE-2023-27316

SnapCenter versions 4.8 through 4.9 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin u…

Fix: after 4.9
Fix from $1,950 2023-10-12
Anti Cheat Tool HIGH 7.8
CVE-2023-38817

An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component. …

Fix: 5.2.1.0+
Fix from $1,950 2023-10-11
Dph 400se Firmware HIGH 8.8
CVE-2023-43960

An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in the Maintenance/Access funct…

No fix yet
Fix from $1,950 2023-10-11
Displaylink MEDIUM 6.7
CVE-2023-4936

It is possible to sideload a compromised DLL during the installation at elevated privilege.

Fix: 11.2+
Fix from $1,600 2023-10-11
Harmonyos CRITICAL 9.8
CVE-2023-44105

Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause feat…

No fix yet
Fix from $2,300 2023-10-11
Harmonyos CRITICAL 9.8
CVE-2023-44106

API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnorma…

No fix yet
Fix from $2,300 2023-10-11