Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Xen HIGH 7.1
CVE-2021-28692

inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operation of the CPU(s) issuing such…

Mitigation only
Fix from $1,950 2021-06-30
Openvpn Client HIGH 7.8
CVE-2021-35523

Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYST…

Fix: 2.0.32+
Fix from $1,950 2021-06-28
Ie Wl Bl Ap Cl Eu Firmware HIGH 8.8
CVE-2021-33538

In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists in the iw_webs account settin…

Fix: after 1.16.18
Fix from $1,950 2021-06-25
Emote Interactive Studio HIGH 7.8
CVE-2021-35448

Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder fe…

No fix yet
Fix from $1,950 2021-06-24
Firefox HIGH 8.8
CVE-2021-23999

If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges t…

Fix: 78.10 / 88.0+
Fix from $1,950 2021-06-24
Firefox MEDIUM 6.5
CVE-2021-29951

The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start …

Fix: 78.10.1 / 87.0+
Fix from $1,600 2021-06-24
Aura Utility Services HIGH 8.8
CVE-2021-25650

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially craft…

Fix: after 7.1.3
Fix from $1,950 2021-06-24
Aura Utility Services HIGH 7.8
CVE-2021-25651

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Af…

Fix: after 7.1.3
Fix from $1,950 2021-06-24
Download Station HIGH 8.8
CVE-2021-34810

Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to exe…

Fix: 3.8.16-3566+
Fix from $1,950 2021-06-18
Defibrillator Dashboard HIGH 7.8
CVE-2021-27483

ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to…

Fix: 2.2+
Fix from $1,950 2021-06-16
Internet HIGH 7.8
CVE-2021-25418

Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activit…

Fix: 14.0.1.62+
Fix from $1,950 2021-06-11
Helpdesk HIGH 8.8
CVE-2021-28814

An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise…

Fix: 3.0.4+
Fix from $1,950 2021-06-11
Computing Improvement Program HIGH 7.8
CVE-2021-0052

Incorrect default privileges in the Intel(R) Computing Improvement Program before version 2.4.6522 may allow an authenticated user to potentially ena…

Fix: 2.4.6522+
Fix from $1,950 2021-06-09
Raspap HIGH 8.8
CVE-2021-33356EPSS 5%

Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /in…

Fix: after 2.6.5
Fix from $1,950 2021-06-09
Windows 10 HIGH 7.8
CVE-2021-31969

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-06-08
Windows 10 HIGH 7.8
CVE-2021-31954

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-06-08
Metasys HIGH 8.8
CVE-2021-27657

Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allow…

Fix: after 11.0
Fix from $1,950 2021-06-04
Qemu HIGH 7.8
CVE-2013-4536

An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on…

Fix: 1.5.3+
Fix from $1,950 2021-05-28
Spring Framework HIGH 7.8
CVE-2021-22118

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation:…

Fix: 5.2.15 / 5.3.7+
Fix from $1,950 2021-05-27
Spacelynk Firmware HIGH 7.8
CVE-2021-22732

Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a code execution issue…

Fix: after 2.6.0
Fix from $1,950 2021-05-26
Spacelynk Firmware HIGH 7.8
CVE-2021-22733

Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause shell access when unau…

Fix: after 2.6.0
Fix from $1,950 2021-05-26
Versa Analytics HIGH 7.8
CVE-2018-16497

In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as…

Mitigation only
Fix from $1,950 2021-05-26
Fusion CRITICAL 9.8
CVE-2020-28904

Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious co…

Fix: after 4.1.8
Fix from $2,300 2021-05-24
Qnd HIGH 7.8
CVE-2021-20713

Privilege escalation vulnerability in QND Advance/Premium/Standard Ver.11.0.4i and earlier allows an attacker who can log in to the PC where the prod…

Fix: after 11.0.4i
Fix from $1,950 2021-05-24
Store Locator Plus HIGH 8.8
CVE-2021-24289

There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their us…

Fix: after 5.5.14
Fix from $1,950 2021-05-17
Total Protection HIGH 7.8
CVE-2021-23891

Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating…

Fix: 16.0.32+
Fix from $1,950 2021-05-12
Windows 10 HIGH 7.8
CVE-2021-31168

Windows Container Manager Service Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-05-11
Windows 10 HIGH 7.8
CVE-2021-31169

Windows Container Manager Service Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-05-11
Openapi Generator MEDIUM 5.5
CVE-2021-21430

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an Op…

Fix: 5.1.1+
Fix from $1,600 2021-05-10
Openapi Generator HIGH 7.0
CVE-2021-21428

Openapi generator is a java tool which allows generation of API client libraries (SDK generation), server stubs, documentation and configuration auto…

Fix: 5.1.0+
Fix from $1,950 2021-05-10