Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Nocodb HIGH 8.8
CVE-2022-2063

Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.

Fix: 0.91.7+
Fix from $1,950 2022-06-13
Access Control HIGH 8.8
CVE-2017-20037

A vulnerability has been found in SICUNET Access Controller 0.32-05z and classified as critical. Affected by this vulnerability is an unknown functio…

No fix yet
Fix from $1,950 2022-06-11
Access Control HIGH 8.8
CVE-2017-20038

A vulnerability was found in SICUNET Access Controller 0.32-05z and classified as critical. Affected by this issue is some unknown functionality of t…

Mitigation only
Fix from $1,950 2022-06-11
Solar Log 250 Firmware CRITICAL 9.8
CVE-2017-20021

A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component Fil…

No fix yet
Fix from $2,300 2022-06-09
Solar Log 250 Firmware CRITICAL 9.8
CVE-2017-20023

A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as critical. This issue affects some unknown processing of the compone…

No fix yet
Fix from $2,300 2022-06-09
Solar Log 250 Firmware CRITICAL 9.8
CVE-2017-20025

A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85. It has been declared as critical. Affected by this vulnerability is an unknown funct…

No fix yet
Fix from $2,300 2022-06-09
Humhub CRITICAL 9.8
CVE-2017-20028

A vulnerability was found in HumHub 0.20.1/1.0.0-beta.3. It has been classified as critical. This affects an unknown part. The manipulation leads to …

No fix yet
Fix from $2,300 2022-06-09
Webyog Monyog Ultimate HIGH 8.8
CVE-2016-15002

A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. T…

No fix yet
Fix from $1,950 2022-06-09
Ajenti HIGH 8.8
CVE-2019-25066EPSS 5%

A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipul…

Patch available
Fix from $1,950 2022-06-09
Registro Elettronico HIGH 8.8
CVE-2019-25068

A vulnerability classified as critical was found in Axios Italia Axios RE 1.7.0/7.0.0. This vulnerability affects unknown code of the file REDefault.…

Mitigation only
Fix from $1,950 2022-06-09
Fedora HIGH 7.8
CVE-2022-31214

A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firej…

Patch available
Fix from $1,950 2022-06-09
Metadefender CRITICAL 9.8
CVE-2022-32272EPSS 9%

OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access co…

Fix: 5.1.2+
Fix from $2,300 2022-06-09
Account HIGH 7.5
CVE-2022-30735

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.

Fix: 13.2.00.6+
Fix from $1,950 2022-06-07
Account MEDIUM 5.3
CVE-2022-30736

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without per…

Fix: 13.2.00.6+
Fix from $1,600 2022-06-07
Account MEDIUM 5.3
CVE-2022-30743

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without per…

Fix: 13.2.00.6+
Fix from $1,600 2022-06-07
Demokratian CRITICAL 9.8
CVE-2020-36542

A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/install3.php. The manipulation…

Patch available
Fix from $2,300 2022-06-07
Debian Linux HIGH 8.8
CVE-2019-9971

PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tc…

No fix yet
Fix from $1,950 2022-06-07
Gateway Plug In HIGH 7.1
CVE-2022-21827

An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could…

Fix: 21.9.1.2+
Fix from $1,950 2022-05-26
Powerdirector HIGH 7.8
CVE-2022-29333

A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.

No fix yet
Fix from $1,950 2022-05-24
Scala Rider Q3 Firmware HIGH 8.8
CVE-2014-125001

A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthen…

No fix yet
Fix from $1,950 2022-05-24
Gitblit CRITICAL 9.8
CVE-2022-31267EPSS 18%

Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as an emailAdd…

No fix yet
Fix from $2,300 2022-05-21
Cilium HIGH 8.2
CVE-2022-29179

Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9…

Fix: 1.9.16 / 1.10.11+
Fix from $1,950 2022-05-20
Trudesk HIGH 8.8
CVE-2022-1770

Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.

Fix: 1.2.2+
Fix from $1,950 2022-05-20
Snap Deploy HIGH 7.8
CVE-2022-30695

Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Snap Deploy (Window…

Fix: 6+
Fix from $1,950 2022-05-16
Rubygems.org HIGH 7.5
CVE-2022-29218

RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allo…

No fix yet
Fix from $1,950 2022-05-13
Zonealarm HIGH 7.8
CVE-2022-23743

Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permiss…

Fix: 15.8.211.192119+
Fix from $1,950 2022-05-11
Android MEDIUM 5.5
CVE-2022-20112

In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change private DNS settings due to a per…

Mitigation only
Fix from $1,600 2022-05-10
Android HIGH 7.8
CVE-2022-20114

In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a pe…

Patch available
Fix from $1,950 2022-05-10
Easyappointments HIGH 8.8
CVE-2022-1397

API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover.

Fix: 1.5.0+
Fix from $1,950 2022-05-10
Bigfix Platform HIGH 7.8
CVE-2021-27765

The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to…

Fix: after 10.0.5
Fix from $1,950 2022-05-06