Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Gen5w L Firmware HIGH 7.8
CVE-2023-26243

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The decryption binary used to decrypt …

No fix yet
Fix from $1,950 2023-04-27
Gen5w L Firmware HIGH 7.8
CVE-2023-26244

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppDMClient binary file, which is …

No fix yet
Fix from $1,950 2023-04-27
Gen5w L Firmware HIGH 7.8
CVE-2023-26245

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is u…

No fix yet
Fix from $1,950 2023-04-27
Gen5w L Firmware HIGH 7.8
CVE-2023-26246

An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR.S5W_L001.001.211214. The AppUpgrade binary file, which is u…

No fix yet
Fix from $1,950 2023-04-27
Clusternet HIGH 8.8
CVE-2023-30622

Clusternet is a general-purpose system for controlling Kubernetes clusters across different environments. An issue in clusternet prior to version 0.1…

Fix: after 0.15.1
Fix from $1,950 2023-04-24
Powerpanel CRITICAL 9.8
CVE-2023-25133

Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Busine…

Fix: after 4.8.6
Fix from $2,300 2023-04-24
Microweber HIGH 8.8
CVE-2023-2240

Improper Privilege Management in GitHub repository microweber/microweber prior to 1.3.4.

Fix: 1.3.4+
Fix from $1,950 2023-04-22
Orion Platform HIGH 7.8
CVE-2022-47505

The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid sys…

Fix: 2023.2+
Fix from $1,950 2023-04-21
Desktop HIGH 7.8
CVE-2023-28122

A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a malicious actor with local access…

Fix: 0.62.3.0+
Fix from $1,950 2023-04-19
Kubewarden Controller HIGH 8.8
CVE-2023-22645

An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get access to the ServiceAccount…

Fix: 1.6.0+
Fix from $1,950 2023-04-19
Vm Virtualbox HIGH 7.8
CVE-2023-21987

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.…

Fix: 6.1.44 / 7.0.8+
Fix from $1,950 2023-04-18
Vm Virtualbox HIGH 8.2
CVE-2023-21990

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.…

Fix: 6.1.44 / 7.0.8+
Fix from $1,950 2023-04-18
Solaris HIGH 7.0
CVE-2023-21896

Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult …

Patch available
Fix from $1,950 2023-04-18
Ecostruxure Control Expert MEDIUM 5.5
CVE-2023-1548

A CWE-269: Improper Privilege Management vulnerability exists that could cause a local user to perform a denial of service through the console server…

Mitigation only
Fix from $1,600 2023-04-18
Spark CRITICAL 9.9
CVE-2023-22946

In Apache Spark versions prior to 3.4.0, applications using spark-submit can specify a 'proxy-user' to run as, limiting privileges. The application c…

Fix: 3.4.0+
Fix from $2,300 2023-04-17
Who CRITICAL 9.8
CVE-2023-27654

An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMultiProvider component.

No fix yet
Fix from $2,300 2023-04-14
Openfeature HIGH 8.8
CVE-2023-29018

The OpenFeature Operator allows users to expose feature flags to applications. Assuming the pre-existence of a vulnerability that allows for arbitrar…

Fix: 0.2.32+
Fix from $1,950 2023-04-14
Super Clean HIGH 7.8
CVE-2023-27651

An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges via the update_info field of the _default_.xml file.

No fix yet
Fix from $1,950 2023-04-14
Apport HIGH 7.8
CVE-2023-1326

A privilege escalation attack was found in apport-cli 2.26.0 and earlier which is similar to CVE-2023-26604. If a system is specially configured to a…

Fix: after 2.26.0
Fix from $1,950 2023-04-13
Eos HIGH 7.8
CVE-2023-24509

On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with R…

Fix: 4.24.11m / 4.25.10m+
Fix from $1,950 2023-04-13
Tightvnc CRITICAL 9.0
CVE-2023-27830

TightVNC before v2.8.75 allows attackers to escalate privileges on the host operating system via replacing legitimate files with crafted files when e…

Fix: 2.8.75+
Fix from $2,300 2023-04-12
Fortideceptor HIGH 8.8
CVE-2022-27487

A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version …

Fix: 3.2.4 / 3.3.3+
Fix from $1,950 2023-04-11
Poweramp CRITICAL 9.8
CVE-2023-27645

An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset p…

No fix yet
Fix from $2,300 2023-04-11
Android MEDIUM 6.7
CVE-2023-20680

In adsp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execu…

Mitigation only
Fix from $1,600 2023-04-06
Android HIGH 7.8
CVE-2023-20655

In mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local code execution with no additional exe…

Mitigation only
Fix from $1,950 2023-04-06
Bhima MEDIUM 6.5
CVE-2023-0959

Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an a…

No fix yet
Fix from $1,600 2023-04-05
Fields MEDIUM 6.5
CVE-2023-28855

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check…

Fix: 1.13.1 / 1.20.4+
Fix from $1,600 2023-04-05
Glpi HIGH 8.1
CVE-2023-28632

GLPI is a free asset and IT management software package. Starting in version 0.83 and prior to versions 9.5.13 and 10.0.7, an authenticated user can …

Fix: 9.5.13 / 10.0.7+
Fix from $1,950 2023-04-05
Acuant Asureid Sentinel HIGH 7.8
CVE-2022-48227

An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows elevation of privileges because it opens Notepad after the installation …

Fix: 5.2.149+
Fix from $1,950 2023-04-04
Acuant Acufill Sdk HIGH 7.8
CVE-2022-48226

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During installation, an EXE gets executed out of C:\Windows\Temp. A standard user c…

Fix: 10.22.02.03+
Fix from $1,950 2023-04-04