Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Directus HIGH 8.8
CVE-2021-26594

In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: Thi…

Fix: after 8.8.1
Fix from $1,950 2021-02-23
Online HIGH 7.8
CVE-2021-25630

"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" che…

Fix: 4.2.13 / 6.4.3+
Fix from $1,950 2021-02-23
Airflow MEDIUM 5.3
CVE-2021-26697

The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h…

Mitigation only
Fix from $1,600 2021-02-17
Web Gateway HIGH 8.8
CVE-2021-23885

Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain elevated privileges through the Us…

Fix: 8.2.17 / 9.2.8+
Fix from $1,950 2021-02-17
M\!dge Firmware HIGH 7.8
CVE-2021-20075

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd.

No fix yet
Fix from $1,950 2021-02-16
Mbconnect24 MEDIUM 6.5
CVE-2020-35557

An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in us…

Fix: after 2.11.2
Fix from $1,600 2021-02-16
Gatemanager 8250 Firmware HIGH 8.1
CVE-2020-29031

An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the passwor…

Fix: 9.0i / 9.2c+
Fix from $1,950 2021-02-15
Replaysorcery HIGH 7.8
CVE-2021-26936

The replay-sorcery program in ReplaySorcery 0.4.0 through 0.5.0, when using the default setuid-root configuration, allows a local attacker to escalat…

Fix: after 0.5.0
Fix from $1,950 2021-02-10
Android HIGH 7.8
CVE-2021-0327

In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lea…

Patch available
Fix from $1,950 2021-02-10
Total Protection HIGH 7.8
CVE-2021-23876

Bypass Remote Procedure call in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary …

Fix: 16.0.30+
Fix from $1,950 2021-02-10
Total Protection HIGH 7.8
CVE-2021-23874 KEV

Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execu…

Fix: 16.0.30+
Fix from $1,950 2021-02-10
Emc Powerscale Onefs HIGH 7.8
CVE-2020-26191

Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain a privilege escalation vulnerability. A user with ISI_PRIV_JOB_ENGINE may use the Permission…

Mitigation only
Fix from $1,950 2021-02-09
Qemu HIGH 8.2
CVE-2020-35517

A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is abl…

Fix: after 5.2.50
Fix from $1,950 2021-01-28
Smartconsole HIGH 7.8
CVE-2020-6024

Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vu…

Mitigation only
Fix from $1,950 2021-01-20
Junos HIGH 7.8
CVE-2021-0223

A local privilege escalation vulnerability in telnetd.real of Juniper Networks Junos OS may allow a locally authenticated shell user to escalate priv…

Mitigation only
Fix from $1,950 2021-01-15
Junos HIGH 7.8
CVE-2021-0204

A sensitive information disclosure vulnerability in delta-export configuration utility (dexp) of Juniper Networks Junos OS may allow a locally authen…

Mitigation only
Fix from $1,950 2021-01-15
Acmailer CRITICAL 9.8
CVE-2021-20618

Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remote attackers to bypass authent…

Fix: after 4.0.2
Fix from $2,300 2021-01-14
Anyconnect Secure Mobility Client MEDIUM 5.5
CVE-2021-1258

A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges …

Fix: 4.9.03047 / 4.9.03049+
Fix from $1,600 2021-01-13
Emui CRITICAL 9.1
CVE-2020-9141

There is a improper privilege management vulnerability in some Huawei smartphone. Successful exploitation of this vulnerability can cause information…

No fix yet
Fix from $2,300 2021-01-13
Windows 10 HIGH 7.3
CVE-2021-1704

Windows Hyper-V Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2021-01-12
Windows 10 HIGH 7.3
CVE-2021-1706

Windows LUAFV Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2021-01-12
Windows 10 HIGH 7.0
CVE-2021-1709

Windows Win32k Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2021-01-12
Sharepoint Enterprise Server HIGH 8.0
CVE-2021-1712

Microsoft SharePoint Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2021-01-12
Sharepoint Enterprise Server HIGH 8.0
CVE-2021-1719

Microsoft SharePoint Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2021-01-12
Windows 10 HIGH 7.8
CVE-2021-1687

Windows WalletService Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2021-01-12
Windows 10 HIGH 7.8
CVE-2021-1688

Windows CSC Service Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2021-01-12
Windows 10 HIGH 7.8
CVE-2021-1689

Windows Multipoint Management Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2021-01-12
Windows 10 HIGH 7.8
CVE-2021-1690

Windows WalletService Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2021-01-12
Windows 10 HIGH 7.8
CVE-2021-1693

Windows CSC Service Elevation of Privilege Vulnerability

No fix yet
Fix from $1,950 2021-01-12
Windows 10 HIGH 7.5
CVE-2021-1694

Windows Update Stack Elevation of Privilege Vulnerability

Mitigation only
Fix from $1,950 2021-01-12