Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Synaman HIGH 7.2
CVE-2022-26251

The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.

Fix: after 5.1
Fix from $1,950 2022-04-06
Android HIGH 8.8
CVE-2021-39772

In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This could lead to local escalation …

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39782

In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This could lead to local escalati…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39783

In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39784

In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission check. This could lead to local e…

Mitigation only
Fix from $1,950 2022-03-30
Iss Blackice Pc Protection CRITICAL 9.8
CVE-2003-5001

A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Dete…

Mitigation only
Fix from $2,300 2022-03-28
Deno CRITICAL 10.0
CVE-2022-24783

Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where…

Fix: 1.20.3+
Fix from $2,300 2022-03-25
Open Web Analytics CRITICAL 9.8
CVE-2022-24637EPSS 99%

Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin…

Fix: 1.7.4+
Fix from $2,300 2022-03-18
Whale MEDIUM 6.1
CVE-2022-24072

The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page vi…

Fix: 3.12.129.18+
Fix from $1,600 2022-03-17
Centum Cs 3000 Firmware HIGH 7.8
CVE-2022-22141

'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL configurat…

Mitigation only
Fix from $1,950 2022-03-11
Ultravnc HIGH 7.8
CVE-2022-24750

UltraVNC is a free and open source remote pc access software. A vulnerability has been found in versions prior to 1.3.8.0 in which the DSM plugin mod…

Fix: 1.3.8.1+
Fix from $1,950 2022-03-10
Android HIGH 7.8
CVE-2022-24931

Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to execute arbi…

Mitigation only
Fix from $1,950 2022-03-10
Android MEDIUM 5.5
CVE-2022-20051

In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service…

Mitigation only
Fix from $1,600 2022-03-10
Windows 10 HIGH 7.8
CVE-2022-23296

Windows Installer Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2022-03-09
Sinumerik Mc Firmware HIGH 7.8
CVE-2022-24408

A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binary on affec…

Fix: 1.15 / 6.15+
Fix from $1,950 2022-03-08
Sinec Network Management System HIGH 7.3
CVE-2022-25311

A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions)…

Fix: 1.0.3+
Fix from $1,950 2022-03-08
Masterstudy Lms CRITICAL 9.8
CVE-2022-0441EPSS 85%

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated use…

Fix: 2.7.6+
Fix from $2,300 2022-03-07
Printix CRITICAL 9.8
CVE-2022-25089EPSS 18%

Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.Persiste…

Fix: after 1.3.1106.0
Fix from $2,300 2022-03-03
Proficy Cimplicitiy HIGH 7.8
CVE-2022-23921

Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is on…

Fix: after 11.1
Fix from $1,950 2022-02-25
Linux Kernel HIGH 7.8
CVE-2022-25636

net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. Thi…

Fix: 5.4.182 / 5.10.103+
Fix from $1,950 2022-02-24
Pritunl Client Electron HIGH 7.8
CVE-2022-25372

Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go.

Fix: 1.2.3019.52a+
Fix from $1,950 2022-02-20
X26 Cogs HIGH 7.2
CVE-2022-23604

x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool for Discord server moderatio…

Fix: 1.10.0+
Fix from $1,950 2022-02-15
Binisoft Windows Firewall Control HIGH 7.8
CVE-2022-25150

In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges.

Fix: 6.8.1.0+
Fix from $1,950 2022-02-14
Video Player CRITICAL 9.8
CVE-2022-24927

Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permis…

Fix: 7.3.15.30+
Fix from $2,300 2022-02-11
Connexium Network Manager CRITICAL 9.8
CVE-2021-22801

A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configured with sp…

Mitigation only
Fix from $2,300 2022-02-11
Emc Integrated System For Microsoft Azure Stack Hub Firmware CRITICAL 9.9
CVE-2021-36302

All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user with stan…

Fix: after 2204
Fix from $2,300 2022-02-09
Chatwoot MEDIUM 6.5
CVE-2021-3813

Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.

Fix: after 2.1.1
Fix from $1,600 2022-02-09
Endpoint Antivirus HIGH 7.8
CVE-2021-37852

ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in …

Fix: 7.3.2055.0 / 7.3.10014.0+
Fix from $1,950 2022-02-09
Fl Switch 2005 Firmware HIGH 8.8
CVE-2022-22509

In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the…

Mitigation only
Fix from $1,950 2022-02-02
Wp Google Map MEDIUM 5.4
CVE-2021-45729

The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to cr…

Fix: 1.8.1+
Fix from $1,600 2022-01-25