Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Bigfix Platform HIGH 7.8
CVE-2021-27766

The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to per…

Fix: after 10.0.5
Fix from $1,950 2022-05-06
Bigfix Platform HIGH 7.8
CVE-2021-27767

The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to pe…

Fix: after 10.0.5
Fix from $1,950 2022-05-06
Argo Workflows HIGH 7.1
CVE-2022-29164

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affected versions an attacker can…

Fix: 3.2.11 / 3.3.5+
Fix from $1,950 2022-05-06
Gatemanager 4250 Firmware MEDIUM 5.4
CVE-2022-25782

Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to access and update privileged inf…

Fix: 9.7.622134021+
Fix from $1,600 2022-05-04
Secure Firewall Threat Defense HIGH 8.8
CVE-2022-20759EPSS 29%

A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower …

Fix: 6.4.0.15 / 6.6.5.2+
Fix from $1,950 2022-05-03
Rancher HIGH 7.2
CVE-2021-36784

A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affec…

Fix: 2.5.13 / 2.6.4+
Fix from $1,950 2022-05-02
Rancher MEDIUM 5.4
CVE-2021-4200

A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restricted-admin role is enabled. …

Fix: 2.5.13 / 2.6.4+
Fix from $1,600 2022-05-02
Metasys Application And Data Server HIGH 8.8
CVE-2021-36207

Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elev…

Fix: 10.1.5 / 11.0.2+
Fix from $1,950 2022-04-29
Psgo HIGH 8.8
CVE-2022-1227

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is d…

Fix: 1.7.2+
Fix from $1,950 2022-04-29
Thinkpad 11e Firmware MEDIUM 6.7
CVE-2022-1107

During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some…

Mitigation only
Fix from $1,600 2022-04-22
Thinkpad X1 Fold Gen 1 Firmware MEDIUM 6.7
CVE-2022-1108

A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploite…

Mitigation only
Fix from $1,600 2022-04-22
Log4jhotpatch HIGH 8.8
CVE-2021-3100

The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to e…

Fix: 1.1-13+
Fix from $1,950 2022-04-19
Hotdog HIGH 8.8
CVE-2021-3101

Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow a container to gain full pri…

Fix: 1.0.1+
Fix from $1,950 2022-04-19
Log4jhotpatch HIGH 8.8
CVE-2022-0070

Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the …

Fix: 1.1-16+
Fix from $1,950 2022-04-19
Hotdog HIGH 8.8
CVE-2022-0071

Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or syscall filters of the target J…

Fix: 1.0.2+
Fix from $1,950 2022-04-19
Windows 10 HIGH 7.8
CVE-2022-26795

Windows Print Spooler Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2022-04-15
Catalyst Sd Wan Manager HIGH 7.3
CVE-2022-20739

A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underly…

Fix: 20.6.1+
Fix from $1,950 2022-04-15
Datamodule Compactplus MEDIUM 6.7
CVE-2020-16238

A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactp…

Mitigation only
Fix from $1,600 2022-04-14
Identity Management Service HIGH 7.8
CVE-2022-22187

An Improper Privilege Management vulnerability in the Windows Installer framework used in the Juniper Networks Juniper Identity Management Service (J…

Fix: 1.4.0+
Fix from $1,950 2022-04-14
Agent HIGH 7.8
CVE-2022-1256

A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through runn…

Fix: 5.7.6+
Fix from $1,950 2022-04-14
Minio HIGH 8.8
CVE-2022-24842

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. A security issue was found where an non-admin user …

Fix: 2022-04-12t06-55-35z+
Fix from $1,950 2022-04-12
Grafana HIGH 8.8
CVE-2022-24812

Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to…

Fix: 8.4.6+
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2021-39797

In several functions of of LauncherApps.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local …

Mitigation only
Fix from $1,950 2022-04-12
Android HIGH 7.8
CVE-2021-39807

In handleNfcStateChanged of SecureNfcEnabler.java, there is a possible way to enable NFC from the Guest account due to a missing permission check. Th…

Patch available
Fix from $1,950 2022-04-12
Emui HIGH 7.5
CVE-2022-22257

The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrit…

No fix yet
Fix from $1,950 2022-04-11
Zyxel Ap Configurator HIGH 7.8
CVE-2022-0556

A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1…

Mitigation only
Fix from $1,950 2022-04-11
Emc Unity Operating Environment MEDIUM 6.7
CVE-2021-36290

Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vuln…

Fix: after 8.1.21.266
Fix from $1,600 2022-04-08
Emc Unity Operating Environment MEDIUM 6.7
CVE-2021-36293

Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vuln…

Fix: after 8.1.21.266
Fix from $1,600 2022-04-08
A\+hrd CRITICAL 9.8
CVE-2022-26676

aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scri…

Mitigation only
Fix from $2,300 2022-04-07
Identity Services Engine MEDIUM 6.5
CVE-2022-20782

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain…

Mitigation only
Fix from $1,600 2022-04-06