Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Windows 10 1809 HIGH 7.0
CVE-2023-36721

Windows Error Reporting Service Elevation of Privilege Vulnerability

Fix: 10.0.17763.4974 / 10.0.19041.3570+
Fix from $1,950 2023-10-10
365 Apps HIGH 8.4
CVE-2023-36569

Microsoft Office Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2023-10-10
Bolt CRITICAL 9.8
CVE-2023-5214

In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.

Fix: 3.27.4+
Fix from $2,300 2023-10-06
Epp Firmware HIGH 7.8
CVE-2023-26236

An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is pos…

Fix: 8.00.22.0010+
Fix from $1,950 2023-10-05
C Bus Toolkit CRITICAL 9.8
CVE-2023-5402

A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the net…

Fix: after 1.16.3
Fix from $2,300 2023-10-04
Ios Xe HIGH 8.8
CVE-2023-20235

A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Softwa…

Fix: 17.3.1+
Fix from $1,950 2023-10-04
Netextender HIGH 7.8
CVE-2023-44217

A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileg…

Fix: after 10.2.336
Fix from $1,950 2023-10-03
Purity\/\/fa HIGH 8.8
CVE-2023-36628

A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.

Fix: after 6.4.5
Fix from $1,950 2023-10-03
I HIGH 7.8
CVE-2023-40375

Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command l…

Patch available
Fix from $1,950 2023-09-28
Scylladb HIGH 8.8
CVE-2023-33972

Scylladb is a NoSQL data store using the seastar framework, compatible with Apache Cassandra. Authenticated users who are authorized to create tables…

Fix: after 5.2.8
Fix from $1,950 2023-09-27
Emui MEDIUM 5.3
CVE-2023-41312

Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatica…

No fix yet
Fix from $1,600 2023-09-27
Glpi HIGH 8.8
CVE-2023-41322

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…

Fix: 10.0.10+
Fix from $1,950 2023-09-27
Glpi HIGH 8.8
CVE-2023-41324

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…

Fix: 10.0.10+
Fix from $1,950 2023-09-27
Glpi HIGH 8.8
CVE-2023-41326EPSS 31%

GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,…

Fix: 10.0.10+
Fix from $1,950 2023-09-27
Emui HIGH 7.5
CVE-2023-41309

Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,950 2023-09-27
Siberiancms CRITICAL 9.8
CVE-2023-39375

SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges

Fix: 4.20.44 / 5.0.4+
Fix from $2,300 2023-09-27
Aria Operations MEDIUM 6.7
CVE-2023-34043

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can esca…

Fix: 4.4+
Fix from $1,600 2023-09-27
Service Provider Management System CRITICAL 9.8
CVE-2023-43457

An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=us…

No fix yet
Fix from $2,300 2023-09-25
Emui HIGH 7.5
CVE-2023-41301

Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.

No fix yet
Fix from $1,950 2023-09-25
Linux Protection HIGH 7.8
CVE-2023-43766

Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Security 15, WithSecu…

Mitigation only
Fix from $1,950 2023-09-22
Connect CRITICAL 9.8
CVE-2023-4662

Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue affects Saphira Connect: bef…

Fix: 9.0+
Fix from $2,300 2023-09-15
Metadefender Kiosk CRITICAL 9.8
CVE-2023-36657

An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrator) can be abused for privile…

Fix: after 4.6.1.9996
Fix from $2,300 2023-09-15
Color Phone MEDIUM 5.3
CVE-2023-42468

The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls without user consent, because…

Fix: after 2.1.8-2
Fix from $1,600 2023-09-13
Office CRITICAL 9.8
CVE-2023-36765

Microsoft Office Elevation of Privilege Vulnerability

Patch available
Fix from $2,300 2023-09-12
Android MEDIUM 5.5
CVE-2023-35671

In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry…

Patch available
Fix from $1,600 2023-09-11
Android HIGH 7.8
CVE-2023-35674 KEV

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local e…

Patch available
Fix from $1,950 2023-09-11
Android HIGH 7.8
CVE-2023-35676

In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe Pending…

Mitigation only
Fix from $1,950 2023-09-11
Android HIGH 7.8
CVE-2023-35667

In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a logic erro…

Patch available
Fix from $1,950 2023-09-11
Identity Services Engine MEDIUM 6.7
CVE-2023-20193

A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary fi…

Fix: after 3.3
Fix from $1,600 2023-09-07
Searchblox HIGH 8.8
CVE-2020-10129

SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to access Admin functionality.

Fix: 9.2.1+
Fix from $1,950 2023-09-06