Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Spring Security Core CRITICAL 9.8
CVE-2022-41923

Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targe…

Fix: 3.3.2 / 4.0.5+
Fix from $2,300 2022-11-23
Modicon M340 Bmxp341000 Firmware HIGH 7.5
CVE-2022-0222

A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller wh…

Fix: 3.50+
Fix from $1,950 2022-11-22
Image Hover Effects Ultimate HIGH 7.2
CVE-2022-42459

Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.

Fix: after 9.7.1
Fix from $1,950 2022-11-18
Sg 2404 Poe Firmware HIGH 7.8
CVE-2022-43308

INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies.

No fix yet
Fix from $1,950 2022-11-18
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2022-43138

Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.

Fix: 14.0.1+
Fix from $2,300 2022-11-17
Powershell Universal HIGH 8.8
CVE-2022-45183

Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve…

Fix: 2.12.6 / 3.4.7+
Fix from $1,950 2022-11-14
Manageengine Mobile Device Manager Plus HIGH 7.8
CVE-2022-41339

In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.

Mitigation only
Fix from $1,950 2022-11-12
Server CRITICAL 9.9
CVE-2022-39395

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server and Vela Worker prior to versio…

Fix: 0.16.0 / 0.17.0+
Fix from $2,300 2022-11-10
Fl Mguard Dm HIGH 7.5
CVE-2021-34579

In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft W…

Mitigation only
Fix from $1,950 2022-11-09
Endpoint Detection And Response CRITICAL 9.8
CVE-2022-37015

Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a typ…

Fix: 4.7.0+
Fix from $2,300 2022-11-08
Cyber Protect Home Office HIGH 7.8
CVE-2022-44732

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) befor…

Fix: 39900+
Fix from $1,950 2022-11-07
Cyber Protect Home Office HIGH 7.8
CVE-2022-44733

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) befor…

Fix: 39900+
Fix from $1,950 2022-11-07
Ipados HIGH 7.8
CVE-2022-42796

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.7 and iPadOS 15.7, macOS Ventura 13. An app may be able to ga…

Fix: 13.0 / 15.7+
Fix from $1,950 2022-11-01
Iphone Os HIGH 7.8
CVE-2022-32907

This issue was addressed with improved checks. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary code with k…

Fix: 9.0 / 16.0+
Fix from $1,950 2022-11-01
Mac Os X HIGH 7.8
CVE-2022-32794

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big …

Fix: 10.15.7 / 11.6.6+
Fix from $1,950 2022-11-01
Engines MEDIUM 5.5
CVE-2022-3369

An Improper Access Control vulnerability in the bdservicehost.exe component, as used in Bitdefender Engines for Windows, allows an attacker to delete…

Fix: 7.92659+
Fix from $1,600 2022-11-01
Automatic User Roles Switcher MEDIUM 6.5
CVE-2022-3419

The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users …

Fix: 1.1.2+
Fix from $1,600 2022-10-31
Fedora HIGH 7.8
CVE-2022-41974

multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. …

Fix: 0.9.2+
Fix from $1,950 2022-10-29
Debian Linux HIGH 8.8
CVE-2022-39286

Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code exec…

Fix: 4.11.2+
Fix from $1,950 2022-10-26
Presto File Server HIGH 8.8
CVE-2022-43749

Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-1601 allows remote authenticated…

Fix: 2.1.2-1601+
Fix from $1,950 2022-10-26
Fabric Operating System HIGH 8.8
CVE-2022-28169

Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, u…

Fix: 8.2.3c / 9.0.1e+
Fix from $1,950 2022-10-25
Emc Powerscale Onefs MEDIUM 6.7
CVE-2022-34438

Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges…

Fix: after 9.4.0.5
Fix from $1,600 2022-10-21
F5os A HIGH 8.8
CVE-2022-41835

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to …

Fix: 1.1.0 / 1.5.0+
Fix from $1,950 2022-10-19
Vm Virtualbox HIGH 7.5
CVE-2022-39422

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.3…

Fix: 6.1.38+
Fix from $1,950 2022-10-18
Junos Os Evolved HIGH 8.8
CVE-2022-22239

An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated…

Fix: 20.4+
Fix from $1,950 2022-10-18
Drive HIGH 7.3
CVE-2022-3421

An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-…

Fix: 64.0+
Fix from $1,950 2022-10-17
Aura Communication Manager MEDIUM 6.7
CVE-2022-2249

Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalat…

Fix: 8.1.3.4+
Fix from $1,600 2022-10-12
Fedora HIGH 7.8
CVE-2022-41032

NuGet Client Elevation of Privilege Vulnerability

Fix: 16.9.26 / 16.11.20+
Fix from $1,950 2022-10-11
Tooljet HIGH 7.5
CVE-2022-3422

Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the fo…

Fix: 1.26.1+
Fix from $1,950 2022-10-07
Aura Application Enablement Services MEDIUM 6.7
CVE-2022-2975

A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative us…

Fix: 8.1.3.5 / 10.1.0.2+
Fix from $1,600 2022-10-06