Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Mac Os X HIGH 7.8
CVE-2021-1839

The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Updat…

Fix: 11.3+
Fix from $1,950 2021-09-08
Ipados HIGH 7.8
CVE-2021-1813

A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS …

Fix: 7.4 / 11.3+
Fix from $1,950 2021-09-08
Owncloud CRITICAL 9.8
CVE-2021-35946

A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate thei…

Fix: 10.8.0+
Fix from $2,300 2021-09-07
Ghost HIGH 7.2
CVE-2021-39192

Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authen…

Fix: 4.10.0+
Fix from $1,950 2021-09-03
Edge MEDIUM 5.3
CVE-2021-36930

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Fix: 93.0.961.38+
Fix from $1,600 2021-09-02
Kindle Firmware HIGH 8.6
CVE-2021-30355EPSS 7%

Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privileges to root.

Fix: after 5.13.4
Fix from $1,950 2021-09-01
Eh600 Firmware HIGH 8.8
CVE-2021-37911

The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attackers can access any system dire…

Fix: after 01.00.30.00
Fix from $1,950 2021-08-30
Contracts CRITICAL 9.8
CVE-2021-39168

OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executo…

Fix: 3.4.2 / 4.3.1+
Fix from $2,300 2021-08-27
Contracts CRITICAL 9.8
CVE-2021-39167

OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executo…

Fix: 3.4.2 / 4.3.1+
Fix from $2,300 2021-08-27
Application Policy Infrastructure Controller HIGH 8.8
CVE-2021-1579

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…

Fix: 3.2 / 4.2+
Fix from $1,950 2021-08-25
Resilient Security Orchestration Automation And Response HIGH 7.5
CVE-2021-29802

IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifie…

Fix: 1.6.1+
Fix from $1,950 2021-08-23
Hm Multiple Roles HIGH 8.8
CVE-2021-24602

The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via thei…

Fix: 1.3+
Fix from $1,950 2021-08-23
Desktop HIGH 7.8
CVE-2021-24038

Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle to an unprivileged process, l…

Fix: 31.1.0.67.507+
Fix from $1,950 2021-08-19
Appdynamics .net Agent HIGH 7.8
CVE-2021-34745

A vulnerability in the AppDynamics .NET Agent for Windows could allow an attacker to leverage an authenticated, local user account to gain SYSTEM pri…

Fix: 21.7+
Fix from $1,950 2021-08-18
Nagios Xi HIGH 7.8
CVE-2021-37345

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scrip…

Fix: 5.8.5+
Fix from $1,950 2021-08-13
Windows 10 Update Assistant HIGH 7.3
CVE-2021-36945

Windows 10 Update Assistant Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-08-12
Windows 10 HIGH 7.8
CVE-2021-34483

Windows Print Spooler Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-08-12
Windows 10 HIGH 7.0
CVE-2021-34487

Windows Event Tracing Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-08-12
Windows 10 HIGH 7.8
CVE-2021-34537

Windows Bluetooth Driver Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-08-12
Windows 7 HIGH 7.8
CVE-2021-36927

Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-08-12
Malware Protection Engine HIGH 7.8
CVE-2021-34471

Microsoft Defender Elevation of Privilege Vulnerability

Fix: 1.1.18400.4+
Fix from $1,950 2021-08-12
Netskope HIGH 8.8
CVE-2020-24576

Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.

Fix: after 77
Fix from $1,950 2021-08-12
Contao HIGH 7.2
CVE-2021-37627

Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged r…

Fix: 4.4.56 / 4.9.18+
Fix from $1,950 2021-08-11
Powerscale Onefs HIGH 7.8
CVE-2021-21567

Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and…

Patch available
Fix from $1,950 2021-08-10
Set User CRITICAL 9.8
CVE-2021-38140

The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AUTHORIZATION after set_user().

Fix: 2.0.1+
Fix from $2,300 2021-08-10
Confd HIGH 7.8
CVE-2021-1572

A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is …

Fix: after 7.5.2
Fix from $1,950 2021-08-04
Harmonyos HIGH 7.8
CVE-2021-22421

A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Eleva…

Mitigation only
Fix from $1,950 2021-08-03
Away From Home HIGH 8.8
CVE-2019-14453

An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus and logged fields, related to j…

No fix yet
Fix from $1,950 2021-08-03
Ecns280 Td Firmware HIGH 7.8
CVE-2021-22396

There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege m…

Mitigation only
Fix from $1,950 2021-08-02
Hmi 3 Control Panel Firmware CRITICAL 9.8
CVE-2021-37167

An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software befor…

Fix: 7.2.5.7+
Fix from $2,300 2021-08-02