Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Virtual Gpu HIGH 7.8
CVE-2023-0192

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can lead to esca…

Fix: 11.12 / 13.7+
Fix from $1,950 2023-04-01
Phpmyfaq HIGH 8.8
CVE-2023-1762

Improper Privilege Management in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

Fix: 3.1.12+
Fix from $1,950 2023-03-31
Flexnet Manager HIGH 7.8
CVE-2017-6894

A vulnerability exists in FlexNet Manager Suite releases 2015 R2 SP3 and earlier (including FlexNet Manager Platform 9.2 and earlier) that affects th…

Fix: after 9.2
Fix from $1,950 2023-03-29
Enterprise Linux HIGH 7.8
CVE-2023-0664

A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows inst…

Fix: 8.0.0+
Fix from $1,950 2023-03-29
Emui CRITICAL 9.8
CVE-2022-48353

Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege escalation, which results in sys…

No fix yet
Fix from $2,300 2023-03-27
Android HIGH 7.8
CVE-2023-21068

In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to local escalati…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-20995

In captureImage of CustomizedSensor.cpp, there is a possible way to bypass the fingerprint unlock due to a logic error in the code. This could lead t…

Mitigation only
Fix from $1,950 2023-03-24
Tailscale HIGH 8.0
CVE-2023-28436

Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the implementation of Tailscale SSH st…

Fix: 1.38.2+
Fix from $1,950 2023-03-23
Hippo4j HIGH 8.8
CVE-2023-27094

An issue found in OpenGoofy Hippo4j v.1.4.3 allows attackers to escalate privileges via the ThreadPoolController of the tenant Management module.

Mitigation only
Fix from $1,950 2023-03-23
Netbackup HIGH 7.1
CVE-2023-28758

An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup c…

Fix: 8.3.0.2+
Fix from $1,950 2023-03-23
Qradar Security Information And Event Manager HIGH 7.2
CVE-2022-43863

IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities…

Fix: 7.4.3+
Fix from $1,950 2023-03-22
Minio HIGH 8.8
CVE-2023-28434 KEVEPSS 7%

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucke…

Fix: 2023-03-20t20-16-18z+
Fix from $1,950 2023-03-22
Clearpass Policy Manager HIGH 7.8
CVE-2023-25590

A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a h…

Fix: after 6.10.8
Fix from $1,950 2023-03-22
Ofcms HIGH 8.8
CVE-2023-24760

An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.

No fix yet
Fix from $1,950 2023-03-16
Minio MEDIUM 6.5
CVE-2023-27589

Minio is a Multi-Cloud Object Storage framework. Starting with RELEASE.2020-12-23T02-24-12Z and prior to RELEASE.2023-03-13T19-46-17Z, a user with `c…

Fix: 2023-03-13t19-46-17z+
Fix from $1,600 2023-03-14
Opendoas HIGH 8.8
CVE-2023-28339

OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI…

Fix: after 6.8.2
Fix from $1,950 2023-03-14
Windows 10 1507 HIGH 7.8
CVE-2023-23412

Windows Accounts Picture Elevation of Privilege Vulnerability

Fix: 10.0.10240.19805 / 10.0.14393.5786+
Fix from $1,950 2023-03-14
Digital Experience Platform HIGH 7.2
CVE-2022-48365

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.

Fix: 1.3.26 / 2.5.31+
Fix from $1,950 2023-03-12
Apex One HIGH 7.8
CVE-2023-25144

An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitr…

Fix: 14.0.11960+
Fix from $1,950 2023-03-10
Fortinac HIGH 7.8
CVE-2022-39953

A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, FortiNAC version 9.1.0 throug…

Fix: after 9.2.6
Fix from $1,950 2023-03-07
Manageengine Assetexplorer MEDIUM 6.5
CVE-2023-26600EPSS 6%

ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 a…

Fix: 6.9 / 11.0+
Fix from $1,600 2023-03-06
Debian Linux HIGH 7.8
CVE-2023-26604

systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "sys…

Fix: 246.7+
Fix from $1,950 2023-03-03
Coocare HIGH 7.8
CVE-2022-45988

starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted file upload.

Fix: 5.364+
Fix from $1,950 2023-03-03
Xwiki HIGH 8.8
CVE-2023-26475EPSS 64%

XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-03-02
Thingsboard HIGH 8.8
CVE-2022-45608

An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an…

Mitigation only
Fix from $1,950 2023-03-01
Ryzen Master HIGH 7.8
CVE-2022-27677

Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading…

Fix: 2.10.1.2287+
Fix from $1,950 2023-03-01
macOS HIGH 7.8
CVE-2023-23497

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. A…

Fix: 11.7.3 / 12.6.3+
Fix from $1,950 2023-02-27
macOS HIGH 7.8
CVE-2022-32900

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6, macOS Big Sur 11.7. An app may be able to gai…

Fix: 11.7 / 12.6+
Fix from $1,950 2023-02-27
Ipados HIGH 7.8
CVE-2022-32949

This issue was addressed with improved checks. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, tvOS 16. An app may be able to execute arbitrary …

Fix: 15.7.1 / 16.0+
Fix from $1,950 2023-02-27
Hilink Ai Life CRITICAL 9.8
CVE-2022-48284

A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability…

No fix yet
Fix from $2,300 2023-02-27