Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
GitLab HIGH 7.5
CVE-2022-2498

An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 trig…

Fix: 15.0.5 / 15.1.4+
Fix from $1,950 2022-08-05
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2022-35243

In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when running in Appliance mode, an…

Fix: 14.1.5 / 15.1.6.1+
Fix from $2,300 2022-08-04
Big Ip Access Policy Manager MEDIUM 6.7
CVE-2022-33962

In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, certai…

Fix: 14.1.5.1 / 15.1.6.1+
Fix from $1,600 2022-08-04
Simple Membership CRITICAL 9.8
CVE-2022-2317

The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of …

Fix: 4.1.3+
Fix from $2,300 2022-08-01
Simple Membership HIGH 8.8
CVE-2022-2273

The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing member…

Fix: 4.1.3+
Fix from $1,950 2022-08-01
Robotic Process Automation MEDIUM 6.5
CVE-2022-34338

IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provi…

Fix: 21.0.3+
Fix from $1,600 2022-08-01
Successfactors Mobile HIGH 8.1
CVE-2022-35291

Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin …

Mitigation only
Fix from $1,950 2022-07-27
Nexus Dashboard MEDIUM 6.7
CVE-2022-20906

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vul…

Fix: 2.2+
Fix from $1,600 2022-07-22
Nexus Dashboard MEDIUM 6.7
CVE-2022-20907

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vul…

Fix: 2.2+
Fix from $1,600 2022-07-22
Forticlient HIGH 7.1
CVE-2022-26113

An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9,…

Fix: after 7.0.3
Fix from $1,950 2022-07-19
Usg Flex 100w Firmware HIGH 7.8
CVE-2022-30526

A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 fir…

Fix: after 5.30
Fix from $1,950 2022-07-19
Fortianalyzer MEDIUM 6.7
CVE-2022-26118

A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a loc…

Fix: 6.4.8 / 7.0.4+
Fix from $1,600 2022-07-18
Acti9 Powertag Link C \(a9xelc10 A\) Firmware MEDIUM 6.8
CVE-2022-34754

A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: A…

Fix: after 2.12.0
Fix from $1,600 2022-07-13
Galaxy Store HIGH 7.8
CVE-2022-33708

Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities…

Fix: 4.5.41.8+
Fix from $1,950 2022-07-12
Galaxy Store HIGH 7.8
CVE-2022-33709

Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities…

Fix: 4.5.41.8+
Fix from $1,950 2022-07-12
Galaxy Store HIGH 7.8
CVE-2022-33710

Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activit…

Fix: 4.5.41.8+
Fix from $1,950 2022-07-12
Pingid Integration For Windows Login HIGH 8.2
CVE-2022-23720

PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT…

Fix: 2.8+
Fix from $1,950 2022-06-30
Pcoip Management Console HIGH 7.8
CVE-2017-20121

A vulnerability was found in Teradici Management Console 2.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functi…

No fix yet
Fix from $1,950 2022-06-30
Teleopti Workforce Management CRITICAL 9.8
CVE-2017-20111

A vulnerability, which was classified as critical, was found in Teleopti WFM 7.1.0. This affects an unknown part of the component Administration. The…

No fix yet
Fix from $2,300 2022-06-29
Ivpn HIGH 7.8
CVE-2017-20112

A vulnerability has been found in IVPN Client 2.6.6120.33863 and classified as critical. Affected by this vulnerability is an unknown functionality. …

No fix yet
Fix from $1,950 2022-06-29
Shadeyouvpn.com HIGH 7.8
CVE-2017-20107

A vulnerability, which was classified as problematic, was found in ShadeYouVPN.com Client 2.0.1.11. Affected is an unknown function. The manipulation…

No fix yet
Fix from $1,950 2022-06-28
Greenlight MEDIUM 5.3
CVE-2022-31039

Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though t…

Fix: 2.12.6+
Fix from $1,600 2022-06-27
Iphone Os HIGH 8.8
CVE-2019-25071

A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or…

Fix: 13.0+
Fix from $1,950 2022-06-25
Db2 HIGH 7.5
CVE-2022-22390

IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege manag…

Mitigation only
Fix from $1,950 2022-06-24
Eagleget HIGH 7.8
CVE-2020-21046

A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2…

Fix: 2.1.6.40+
Fix from $1,950 2022-06-24
Sepcos Control And Protection Relay Firmware CRITICAL 9.8
CVE-2022-2104

The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash).

Fix: 1.23.21 / 1.24.8+
Fix from $2,300 2022-06-24
Local Run Manager CRITICAL 9.8
CVE-2022-1517

LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can al…

Fix: after 3.1
Fix from $2,300 2022-06-24
Pra Es8p2s Firmware CRITICAL 9.8
CVE-2022-32535

The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this c…

Fix: after 1.01.05
Fix from $2,300 2022-06-23
Pra Es8p2s Firmware HIGH 8.8
CVE-2022-32536

The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This woul…

Fix: after 1.01.05
Fix from $1,950 2022-06-23
Go MEDIUM 5.3
CVE-2022-29526

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function co…

Fix: 1.17.10 / 1.18.2+
Fix from $1,600 2022-06-23