Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Operator Terminal Expert Runtime HIGH 7.8
CVE-2020-7544

A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege e…

Fix: 3.1+
Fix from $1,950 2020-11-19
Rsg35 Firmware HIGH 8.8
CVE-2020-12495

Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. Th…

Fix: 2.0.0+
Fix from $1,950 2020-11-19
Expressway MEDIUM 6.5
CVE-2020-3482

A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote …

Mitigation only
Fix from $1,600 2020-11-18
Iot Field Network Director HIGH 8.7
CVE-2020-26072

A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify informat…

Fix: 4.6.1+
Fix from $1,950 2020-11-18
Virtual Apps And Desktops HIGH 8.8
CVE-2020-8269

An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285…

Fix: 7.6 / 7.15+
Fix from $1,950 2020-11-16
Rconfig CRITICAL 9.8
CVE-2020-13638EPSS 77%

lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been f…

Fix: 3.9.7+
Fix from $2,300 2020-11-13
Pan Os HIGH 7.5
CVE-2020-2022

An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administ…

Fix: 8.1.17 / 9.0.11+
Fix from $1,950 2020-11-12
Azure Sphere MEDIUM 5.4
CVE-2020-16993

Azure Sphere Elevation of Privilege Vulnerability

Fix: 20.08+
Fix from $1,600 2020-11-11
Ubuntu Linux HIGH 7.8
CVE-2020-16122

PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of…

Mitigation only
Fix from $1,950 2020-11-07
Sd Wan HIGH 7.8
CVE-2020-3593

A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating syste…

Fix: 20.1.2 / 20.3.1+
Fix from $1,950 2020-11-06
Sd Wan HIGH 7.8
CVE-2020-3594

A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating syste…

Fix: 20.1.2 / 20.3.2+
Fix from $1,950 2020-11-06
Sd Wan HIGH 7.8
CVE-2020-3595

A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating…

Fix: 20.1.2 / 20.3.2+
Fix from $1,950 2020-11-06
Sd Wan HIGH 7.8
CVE-2020-3600

A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating syste…

Fix: 20.1.2 / 20.3.2+
Fix from $1,950 2020-11-06
Identity Services Engine MEDIUM 6.7
CVE-2020-27122

A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to…

Fix: 3.0.0+
Fix from $1,600 2020-11-06
Prolinos HIGH 7.8
CVE-2020-28046

An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate t…

Fix: after 2.4.161.8859r
Fix from $1,950 2020-11-02
Router Manager CRITICAL 9.8
CVE-2020-27654

Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands…

Fix: 1.2.4-8081+
Fix from $2,300 2020-10-29
Router Manager CRITICAL 10.0
CVE-2020-27655

Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via i…

Fix: 1.2.4-8081+
Fix from $2,300 2020-10-29
Winston Firmware HIGH 7.8
CVE-2020-16262

Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation.

No fix yet
Fix from $1,950 2020-10-28
Airwave Glass HIGH 8.8
CVE-2020-7125

A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

Fix: 1.3.2+
Fix from $1,950 2020-10-26
Fruitywifi HIGH 7.8
CVE-2020-24848

FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local p…

Fix: after 2.4
Fix from $1,950 2020-10-23
Taurus An00b Firmware HIGH 7.8
CVE-2020-9112

Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability. Due to lack of privilege restrictions on some of…

Fix: 10.1.0.156+
Fix from $1,950 2020-10-19
Windows 10 HIGH 7.8
CVE-2020-16940

<p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who…

Patch available
Fix from $1,950 2020-10-16
Windows 10 HIGH 7.8
CVE-2020-16902

<p>An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an …

Patch available
Fix from $1,950 2020-10-16
Application And Change Control HIGH 8.2
CVE-2020-7334

Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators …

Fix: 8.3.2+
Fix from $1,950 2020-10-15
Total Protection HIGH 8.8
CVE-2020-7330

Privilege Escalation vulnerability in McAfee Total Protection (MTP) trial prior to 4.0.176.1 allows local users to schedule tasks which call maliciou…

Fix: 4.0.176.1+
Fix from $1,950 2020-10-14
Dca Vantage Analyzer Firmware MEDIUM 6.8
CVE-2020-15797

A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 r…

Fix: 4.5.0.0+
Fix from $1,600 2020-10-13
Fedora HIGH 7.8
CVE-2020-26880

Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration…

Fix: after 6.2.56
Fix from $1,950 2020-10-07
Elementor Pro HIGH 8.8
CVE-2020-26596EPSS 6%

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because o…

Fix: after 3.0.5
Fix from $1,950 2020-10-07
Nextcloud Server MEDIUM 6.5
CVE-2020-8223

A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assi…

No fix yet
Fix from $1,600 2020-10-05
Ios Xe HIGH 7.8
CVE-2020-3393

A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to r…

Mitigation only
Fix from $1,950 2020-09-24