Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Coins Construction Cloud HIGH 8.8
CVE-2021-45222

An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is vulnerable to privilege esca…

Patch available
Fix from $1,950 2022-01-24
Debian Linux HIGH 8.8
CVE-2022-21699

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python prog…

Fix: 7.16.3 / 7.31.1+
Fix from $1,950 2022-01-19
GitLab MEDIUM 6.5
CVE-2022-0090

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configure…

Fix: 14.4.5 / 14.5.3+
Fix from $1,600 2022-01-18
Panda Antivirus HIGH 7.8
CVE-2021-34998

This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Free Antivirus 20.2.0.0. An attacker mus…

Fix: 20.02.00+
Fix from $1,950 2022-01-13
Fedora HIGH 8.6
CVE-2021-43860

Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the…

Fix: 1.10.6+
Fix from $1,950 2022-01-12
Caldera HIGH 8.1
CVE-2021-42562

An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modi…

Fix: after 2.8.1
Fix from $1,950 2022-01-12
Edge Chromium MEDIUM 6.1
CVE-2022-21970

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 97.0.1072.55+
Fix from $1,600 2022-01-11
Windows 10 HIGH 7.8
CVE-2022-21902

Windows DWM Core Library Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2022-01-11
Shelljs HIGH 7.1
CVE-2022-0144

shelljs is vulnerable to Improper Privilege Management

Fix: 0.8.5+
Fix from $1,950 2022-01-11
Android MEDIUM 5.5
CVE-2022-22263

Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.

Mitigation only
Fix from $1,600 2022-01-10
Apex One HIGH 7.8
CVE-2021-45440

A unnecessary privilege vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security 10.0 SP1 (on-prem versions only) could all…

Patch available
Fix from $1,950 2022-01-10
Netskope HIGH 7.8
CVE-2021-41388

Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation of nsAuxiliarySvc process do…

Fix: 89+
Fix from $1,950 2022-01-04
Application And Change Control HIGH 7.8
CVE-2021-31833

Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally logged in att…

Fix: 8.3.4+
Fix from $1,950 2022-01-04
Harmonyos CRITICAL 9.1
CVE-2021-39982

Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerability may read and write arbitrar…

Mitigation only
Fix from $2,300 2022-01-03
Minio HIGH 8.8
CVE-2021-43858EPSS 35%

MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTT…

Fix: 2021-12-27t07-23-18z+
Fix from $1,950 2021-12-27
Zxin10 Cms HIGH 7.8
CVE-2021-21750

ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task modification privilege, an attac…

Fix: after 3.01.01.04
Fix from $1,950 2021-12-27
Mac Os X MEDIUM 6.8
CVE-2018-4478

A validation issue was addressed with improved logic. This issue is fixed in macOS High Sierra 10.13.5, Security Update 2018-003 Sierra, Security Upd…

Fix: 10.11.6 / 10.12.6+
Fix from $1,600 2021-12-23
R Seenet HIGH 7.8
CVE-2021-21911

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A s…

No fix yet
Fix from $1,950 2021-12-22
Amegaview HIGH 7.8
CVE-2021-27445

Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges on the device.

Fix: after 3.0
Fix from $1,950 2021-12-21
Emc Avamar Server HIGH 7.2
CVE-2021-36316

Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability in AUI. A malicious user with…

Patch available
Fix from $1,950 2021-12-21
Sulu HIGH 7.2
CVE-2021-43835

Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who have access to any subset of…

Fix: 2.2.18 / 2.3.8+
Fix from $1,950 2021-12-15
Patrowlmanager HIGH 7.5
CVE-2021-43828

PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) h…

Fix: 1.7.7+
Fix from $1,950 2021-12-14
GitLab HIGH 8.8
CVE-2021-39937

A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions st…

Fix: 14.3.6 / 14.4.4+
Fix from $1,950 2021-12-13
GitLab HIGH 7.1
CVE-2021-39944

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, …

Fix: 14.3.6 / 14.4.4+
Fix from $1,950 2021-12-13
Debian Linux MEDIUM 6.5
CVE-2021-43528

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive ch…

Fix: 91.4.0+
Fix from $1,600 2021-12-08
Apm Agent HIGH 7.8
CVE-2021-37941

A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application runn…

Fix: after 1.26.0
Fix from $1,950 2021-12-08
Worry Free Business Security HIGH 7.8
CVE-2021-44019

An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on af…

Mitigation only
Fix from $1,950 2021-12-03
Worry Free Business Security HIGH 7.8
CVE-2021-44020

An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on af…

Mitigation only
Fix from $1,950 2021-12-03
Worry Free Business Security HIGH 7.8
CVE-2021-44021

An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on af…

Mitigation only
Fix from $1,950 2021-12-03
Windows 10 Update Assistant MEDIUM 5.5
CVE-2021-43211

Windows 10 Update Assistant Elevation of Privilege Vulnerability

Patch available
Fix from $1,600 2021-11-24