Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Real Estate Manager MEDIUM 6.5
CVE-2023-4239

The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restrict…

Fix: after 6.7.1
Fix from $1,600 2023-08-09
Rooms HIGH 7.8
CVE-2023-39211

Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable a…

Fix: 5.15.5+
Fix from $1,950 2023-08-08
Ops Manager Server HIGH 7.2
CVE-2023-4009

In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admi…

Fix: 5.0.22 / 6.0.17+
Fix from $1,950 2023-08-08
Cryptomator HIGH 7.8
CVE-2023-39520

Cryptomator encrypts data being stored on cloud infrastructure. The MSI installer provided on the homepage for Cryptomator version 1.9.2 allows local…

Fix: 1.9.3+
Fix from $1,950 2023-08-07
Wp Ultimate Csv Importer HIGH 8.8
CVE-2023-4140

The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient r…

Fix: after 7.9.8
Fix from $1,950 2023-08-04
Broadworks Application Delivery Platform HIGH 7.8
CVE-2023-20216

A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevat…

Fix: 23.0.2023.05 / 24.0.2023.05+
Fix from $1,950 2023-08-03
Brocade Fabric Operating System HIGH 7.8
CVE-2023-31432

Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could …

Fix: 9.1.1c+
Fix from $1,950 2023-08-02
Cryptomator HIGH 7.8
CVE-2023-37907

Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI installer provided on the homep…

Fix: 1.9.2+
Fix from $1,950 2023-07-25
Kubepi HIGH 8.8
CVE-2023-37917

KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can become admin by editing the `isadm…

Fix: 1.6.5+
Fix from $1,950 2023-07-21
Edge Chromium MEDIUM 6.5
CVE-2023-38187

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 115.0.1901.183+
Fix from $1,600 2023-07-21
Netscaler Application Delivery Controller HIGH 8.0
CVE-2023-3467

Privilege Escalation to root administrator (nsroot)

Fix: 12.1-55.297 / 13.0-91.13+
Fix from $1,950 2023-07-19
Routeros HIGH 7.2
CVE-2023-30799

MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attack…

Fix: 6.49.7+
Fix from $1,950 2023-07-19
Solaris HIGH 7.8
CVE-2023-22023

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Interface). The supported version that is affected is 11. E…

Patch available
Fix from $1,950 2023-07-18
I HIGH 7.8
CVE-2023-30988

The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor with command…

Patch available
Fix from $1,950 2023-07-16
I HIGH 7.8
CVE-2023-30989

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access t…

Patch available
Fix from $1,950 2023-07-16
Razer Central HIGH 7.8
CVE-2023-3513

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access…

Fix: after 7.11.0.558
Fix from $1,950 2023-07-14
Razer Central HIGH 7.8
CVE-2023-3514

Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access…

Fix: after 7.11.0.558
Fix from $1,950 2023-07-14
Secure Access Client HIGH 7.8
CVE-2023-24491

A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an …

Fix: 23.5.1.3+
Fix from $1,950 2023-07-11
Infrasuite Device Master CRITICAL 9.8
CVE-2023-30765

​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege …

Fix: 1.0.7+
Fix from $2,300 2023-07-10
Db2 HIGH 7.8
CVE-2023-27558

IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted servic…

Patch available
Fix from $1,950 2023-07-10
Db2 MEDIUM 6.5
CVE-2023-29256

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper pri…

Mitigation only
Fix from $1,600 2023-07-10
Quantastor HIGH 7.8
CVE-2021-42082

Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl 'localhost:8154/qstor/qs_upgr…

Fix: 6.0.0.355+
Fix from $1,950 2023-07-10
Emui HIGH 7.5
CVE-2022-48515

Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $1,950 2023-07-06
Emui CRITICAL 9.8
CVE-2021-46894

Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation.

Mitigation only
Fix from $2,300 2023-07-06
Android MEDIUM 5.5
CVE-2023-30642

Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege functio…

Mitigation only
Fix from $1,600 2023-07-06
Dgx A100 Firmware HIGH 7.8
CVE-2023-25521

NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privileges by leveraging a weakness whe…

Fix: 1.21+
Fix from $1,950 2023-07-04
Android MEDIUM 6.8
CVE-2023-21513

Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in w…

Mitigation only
Fix from $1,600 2023-06-28
Edge Chromium HIGH 8.2
CVE-2021-31937

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 91.0.864.37+
Fix from $1,950 2023-06-28
Secure Workload MEDIUM 6.5
CVE-2023-20136

A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to exec…

Fix: 3.7.1.40+
Fix from $1,600 2023-06-28
Apex One HIGH 7.8
CVE-2023-34146

An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca…

Fix: 14.0.12518+
Fix from $1,950 2023-06-26