Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Storage Plug In HIGH 8.8
CVE-2022-2637

Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privile…

Mitigation only
Fix from $1,950 2022-10-06
Vnc Server HIGH 7.8
CVE-2022-41975

RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI installer Repair mode.

Fix: 6.11.0 / 6.22.826+
Fix from $1,950 2022-09-30
Smart Evision HIGH 8.8
CVE-2022-39032

Smart eVision has an improper privilege management vulnerability. A remote attacker with general user privilege can exploit this vulnerability to esc…

Mitigation only
Fix from $1,950 2022-09-28
Zonealarm HIGH 8.8
CVE-2022-41604

Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for t…

Fix: 15.8.211.19229+
Fix from $1,950 2022-09-27
Ipados HIGH 7.8
CVE-2022-32826

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8…

Fix: 8.7 / 10.15.7+
Fix from $1,950 2022-09-23
Ipados HIGH 7.8
CVE-2022-32829

This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to execute ar…

Fix: 12.5 / 15.6+
Fix from $1,950 2022-09-23
macOS HIGH 7.8
CVE-2022-32801

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5. An app may be able to gain root privileges.

Fix: 12.5+
Fix from $1,950 2022-09-23
Ipados HIGH 7.8
CVE-2022-32819

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS …

Fix: 8.7 / 10.15.7+
Fix from $1,950 2022-09-23
Endpoint Manager MEDIUM 6.7
CVE-2022-30121

The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is…

Fix: 2021.1.1+
Fix from $1,600 2022-09-23
Desktop HIGH 7.8
CVE-2022-35257

A local privilege escalation vulnerability in UI Desktop for Windows (Version 0.55.1.2 and earlier) allows a malicious actor with local access to a W…

Fix: 0.55.3.17+
Fix from $1,950 2022-09-23
Octoprint HIGH 8.8
CVE-2022-3068

Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.

Fix: 1.8.3+
Fix from $1,950 2022-09-21
Cpx Cmxx Firmware HIGH 7.5
CVE-2022-3079

Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a…

Fix: after 2.0.12
Fix from $1,950 2022-09-20
Biostar 2 HIGH 8.8
CVE-2022-38351

A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administrator via a crafted PUT request…

No fix yet
Fix from $1,950 2022-09-19
Apex One HIGH 7.8
CVE-2022-40142

A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service agents could allow a…

Patch available
Fix from $1,950 2022-09-19
Emui CRITICAL 9.8
CVE-2022-39007

The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escala…

No fix yet
Fix from $2,300 2022-09-16
Mhyprot2 MEDIUM 6.5
CVE-2020-36603

The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not adequately restrict unprivileged function calls, allow…

No fix yet
Fix from $1,600 2022-09-14
Db2 MEDIUM 6.5
CVE-2022-22483

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized …

Patch available
Fix from $1,600 2022-09-13
Matrix Irc Bridge HIGH 8.8
CVE-2022-39203

matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the…

Fix: 0.35.0+
Fix from $1,950 2022-09-13
Matrix Irc Bridge MEDIUM 6.3
CVE-2022-39202

matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in…

Fix: 0.35.0+
Fix from $1,600 2022-09-13
Android MEDIUM 5.3
CVE-2022-36861

Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI priv…

Mitigation only
Fix from $1,600 2022-09-09
Ubuntu Touch HIGH 7.8
CVE-2022-40297

UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode is only four digits, far below…

No fix yet
Fix from $1,950 2022-09-09
Gocd MEDIUM 5.5
CVE-2022-36088

GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately rest…

Fix: 22.2.0+
Fix from $1,600 2022-09-07
Xwiki HIGH 8.8
CVE-2022-31166

XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Starting in versions 11.3.7, 11.0.3, and 12.0RC1, it is possib…

Fix: 13.10.4 / 14.2+
Fix from $1,950 2022-09-07
Fortisoar HIGH 7.8
CVE-2022-30298

An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify s…

Fix: 7.0.3+
Fix from $1,950 2022-09-06
Fortiadc MEDIUM 6.5
CVE-2021-43076

An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and …

Fix: after 6.1.5
Fix from $1,600 2022-09-06
Ip Office HIGH 7.8
CVE-2021-25657

A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate…

Fix: 11.1+
Fix from $1,950 2022-09-02
Hawk HIGH 8.8
CVE-2021-3020

An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), …

Fix: after 2.3.0-15
Fix from $1,950 2022-08-26
Ipados HIGH 7.8
CVE-2022-32840

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.5, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app may be able …

Fix: 8.7 / 12.5+
Fix from $1,950 2022-08-24
Android HIGH 7.5
CVE-2021-0891

An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Product: AndroidVersions: Androi…

Mitigation only
Fix from $1,950 2022-08-24
Tools HIGH 7.8
CVE-2022-31676

VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access …

Fix: 10.3.25 / 12.1.0+
Fix from $1,950 2022-08-23