Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Apex One HIGH 7.8
CVE-2023-34147

An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca…

Fix: 14.0.12518+
Fix from $1,950 2023-06-26
Apex One HIGH 7.8
CVE-2023-34148

An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca…

Fix: 14.0.12518+
Fix from $1,950 2023-06-26
Xwiki HIGH 8.1
CVE-2023-34465

XWiki Platform is a generic wiki platform. Starting in version 11.8-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.2, `Mail.MailConfig` can be ed…

Fix: 14.4.8 / 14.10.6+
Fix from $1,950 2023-06-23
Streampipes HIGH 8.8
CVE-2023-31469

A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user wi…

Fix: after 0.91.0
Fix from $1,950 2023-06-23
Asika Airscale Firmware HIGH 7.8
CVE-2023-25185

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN…

Mitigation only
Fix from $1,950 2023-06-16
Asika Airscale Firmware HIGH 7.8
CVE-2023-25188

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from …

Mitigation only
Fix from $1,950 2023-06-16
Cyber Security HIGH 7.8
CVE-2023-2847

During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with the affected ESET product instal…

Fix: 7.3.3600.0 / 7.3.3700.0+
Fix from $1,950 2023-06-15
Web Element Manager HIGH 7.8
CVE-2023-26062

A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute…

Fix: 22r1+
Fix from $1,950 2023-06-14
Reviewx HIGH 8.8
CVE-2023-2833EPSS 17%

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on th…

Fix: after 1.6.13
Fix from $1,950 2023-06-06
Advanced Cluster Management For Kubernetes HIGH 7.8
CVE-2023-3027

The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value…

Mitigation only
Fix from $1,950 2023-06-05
Splunk App For Stream CRITICAL 9.9
CVE-2023-32713

In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Str…

Fix: 8.1.1+
Fix from $2,300 2023-06-01
Deno Runtime CRITICAL 9.8
CVE-2023-33966

Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` …

Mitigation only
Fix from $2,300 2023-05-31
Edjing Mix CRITICAL 9.8
CVE-2023-29734

An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database.

No fix yet
Fix from $2,300 2023-05-30
Ckan HIGH 8.8
CVE-2023-32696

CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the `ckan` user (equivalen…

Fix: 2.9.9+
Fix from $1,950 2023-05-30
Gs1900 8 Firmware MEDIUM 6.7
CVE-2022-45853

The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could…

Mitigation only
Fix from $1,600 2023-05-30
Cassandra HIGH 7.8
CVE-2023-30601

Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This iss…

Fix: 4.0.10 / 4.1.2+
Fix from $1,950 2023-05-30
Inlong CRITICAL 9.8
CVE-2023-31062

Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.…

Fix: after 1.6.0
Fix from $2,300 2023-05-22
Emui HIGH 7.5
CVE-2023-1693

The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.

Fix: 3.1.0+
Fix from $1,950 2023-05-20
Emui HIGH 7.5
CVE-2023-1694

The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.

Fix: 3.1.0+
Fix from $1,950 2023-05-20
Agent HIGH 7.8
CVE-2022-45452

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acron…

Fix: 15+
Fix from $1,950 2023-05-18
Secureanywhere MEDIUM 5.5
CVE-2023-29819

An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a craft…

Fix: after 9.0.33.39
Fix from $1,600 2023-05-12
Portal For Arcgis MEDIUM 5.4
CVE-2023-25834

Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to acces…

Fix: after 10.9.1
Fix from $1,600 2023-05-09
Yershop HIGH 7.1
CVE-2020-23362

Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter.

No fix yet
Fix from $1,950 2023-05-09
Edge Chromium HIGH 7.5
CVE-2023-29350

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 113.0.1774.35+
Fix from $1,950 2023-05-05
Rancher CRITICAL 9.9
CVE-2023-22651

Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook…

Fix: after 2.7.2
Fix from $2,300 2023-05-04
Cyber Backup HIGH 8.8
CVE-2022-3405EPSS 5%

Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acron…

No fix yet
Fix from $1,950 2023-05-03
Thinkagile Hx5530 Firmware MEDIUM 5.9
CVE-2023-29056

A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be confi…

Fix: 2.93_afbt30p / 3.72_tei388s+
Fix from $1,600 2023-04-28
Iscan Firmware CRITICAL 9.8
CVE-2023-1966

Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor co…

Fix: after 1.3.1
Fix from $2,300 2023-04-28
A921 Firmware MEDIUM 6.6
CVE-2023-30024

The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access…

No fix yet
Fix from $1,600 2023-04-28
Edge Chromium MEDIUM 5.7
CVE-2023-28261

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 110.0.1587.78 / 111.0.1661.54+
Fix from $1,600 2023-04-27