Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Android MEDIUM 5.5
CVE-2023-30713

Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change som…

Mitigation only
Fix from $1,600 2023-09-06
macOS HIGH 7.8
CVE-2023-32426

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may be able to gain root privileges.

Fix: 13.3+
Fix from $1,950 2023-09-06
Pro Video Formats HIGH 8.8
CVE-2023-29166

A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may be able to elevate privileges.

Fix: 2.2.5+
Fix from $1,950 2023-09-06
Patrol Agent HIGH 7.8
CVE-2020-35593

BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.

Fix: after 20.08.00
Fix from $1,950 2023-09-05
Knowstreaming HIGH 8.8
CVE-2023-40918

KnowStreaming 3.3.0 is vulnerable to Escalation of Privileges. Unauthorized users can create a new user with an admin role.

No fix yet
Fix from $1,950 2023-09-05
Icecms CRITICAL 9.8
CVE-2023-36100

An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/U…

No fix yet
Fix from $2,300 2023-09-01
Memos HIGH 8.8
CVE-2023-4697

Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

Fix: 0.13.2+
Fix from $1,950 2023-09-01
Agent HIGH 7.8
CVE-2023-41743

Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Off…

Mitigation only
Fix from $1,950 2023-08-31
Sel 5037 Sel Grid Configurator CRITICAL 9.8
CVE-2023-31175

An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attac…

Fix: 4.5.0.20+
Fix from $2,300 2023-08-31
Agent HIGH 7.8
CVE-2022-45451

Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Off…

Fix: 40173+
Fix from $1,950 2023-08-31
Wp Project Manager HIGH 8.8
CVE-2023-3636

The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restric…

Fix: 2.6.5+
Fix from $1,950 2023-08-31
Emergency Responder HIGH 7.2
CVE-2023-20266

A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Managem…

Mitigation only
Fix from $1,950 2023-08-30
Powerscale Onefs HIGH 8.8
CVE-2023-32457

Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote attacker with low privileges could…

Fix: after 9.5.0.3
Fix from $1,950 2023-08-29
Chrome CRITICAL 9.6
CVE-2019-13690

Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalat…

Fix: 75.0.3770.80+
Fix from $2,300 2023-08-25
Node.js HIGH 7.5
CVE-2023-32559

A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the de…

Fix: after 20.5.0
Fix from $1,950 2023-08-24
Charitable CRITICAL 9.8
CVE-2023-4404

The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insuffi…

Fix: after 1.7.0.12
Fix from $2,300 2023-08-23
Robotic Process Automation CRITICAL 9.8
CVE-2023-38734

IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users…

Fix: after 21.0.7.1
Fix from $2,300 2023-08-22
Data Master MEDIUM 5.5
CVE-2023-3699

An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage device…

Fix: 4.2.3.rk91+
Fix from $1,600 2023-08-22
Syncthru Web Service HIGH 7.5
CVE-2021-35309

An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.

No fix yet
Fix from $1,950 2023-08-22
Powerscale Onefs HIGH 7.8
CVE-2023-32487

Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentially exploit t…

Fix: after 9.5.0.3
Fix from $1,950 2023-08-16
Powerscale Onefs MEDIUM 6.7
CVE-2023-32490

Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentially exploit t…

Fix: after 9.5.0.3
Fix from $1,600 2023-08-16
Android HIGH 7.8
CVE-2023-21272

In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privil…

Patch available
Fix from $1,950 2023-08-14
Android HIGH 7.8
CVE-2023-21269

In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. Thi…

Patch available
Fix from $1,950 2023-08-14
I HIGH 7.8
CVE-2023-38721

The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain …

Patch available
Fix from $1,950 2023-08-14
Horizon HIGH 8.0
CVE-2023-0872

The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elev…

Fix: 32.0.2+
Fix from $1,950 2023-08-14
Endpoint Antivirus HIGH 7.8
CVE-2023-3160

The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having pro…

Mitigation only
Fix from $1,950 2023-08-14
Premium Packages Sell Digital Products Securely MEDIUM 6.5
CVE-2023-4293

The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.…

Fix: after 5.7.5
Fix from $1,600 2023-08-12
Ruoyi CRITICAL 9.8
CVE-2021-28411

An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote a…

No fix yet
Fix from $2,300 2023-08-11
Android HIGH 7.8
CVE-2023-30680

Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

Mitigation only
Fix from $1,950 2023-08-10
Wp 6070 Wvps Firmware HIGH 7.2
CVE-2023-37859

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker …

Fix: 4.0.10+
Fix from $1,950 2023-08-09