Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Fedora HIGH 7.8
CVE-2020-26880

Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration…

Fix: after 6.2.56
Fix from $1,950 2020-10-07
Elementor Pro HIGH 8.8
CVE-2020-26596EPSS 6%

The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because o…

Fix: after 3.0.5
Fix from $1,950 2020-10-07
Nextcloud Server MEDIUM 6.5
CVE-2020-8223

A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assi…

No fix yet
Fix from $1,600 2020-10-05
Ios Xe HIGH 7.8
CVE-2020-3393

A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to r…

Mitigation only
Fix from $1,950 2020-09-24
Ios Xe HIGH 7.2
CVE-2020-3396

A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical …

Mitigation only
Fix from $1,950 2020-09-24
Pexip Infinity CRITICAL 9.8
CVE-2015-4719

The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.

Fix: 10+
Fix from $2,300 2020-09-24
Fedora HIGH 7.8
CVE-2020-25595

An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been ide…

Fix: after 4.14.0
Fix from $1,950 2020-09-23
Application Delivery Controller Firmware HIGH 8.8
CVE-2020-8247

Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.18…

Fix: 10.2.7b / 11.0.3f+
Fix from $1,950 2020-09-18
Android MEDIUM 6.7
CVE-2020-0403

In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation…

Mitigation only
Fix from $1,600 2020-09-17
Spamtitan HIGH 7.2
CVE-2020-24046

A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a smal…

No fix yet
Fix from $1,950 2020-09-17
Android MEDIUM 5.5
CVE-2020-0404

In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalati…

Mitigation only
Fix from $1,600 2020-09-17
Android HIGH 7.8
CVE-2020-0074

In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for a…

Patch available
Fix from $1,950 2020-09-17
Exchange Server HIGH 8.4
CVE-2020-16875EPSS 47%

<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who s…

Patch available
Fix from $1,950 2020-09-11
Experience Manager HIGH 7.5
CVE-2020-9733

An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If e…

Fix: after 6.5.5.0
Fix from $1,950 2020-09-10
Mcafee Agent HIGH 7.0
CVE-2020-7311

Privilege Escalation vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to assume SYSTEM rights during…

Fix: 5.6.6+
Fix from $1,950 2020-09-10
License Management Utility HIGH 7.8
CVE-2020-10056

A vulnerability has been identified in License Management Utility (LMU) (All versions < V2.4). The lmgrd service of the affected application is execu…

Fix: 2.4+
Fix from $1,950 2020-09-09
Mvision Endpoint MEDIUM 6.1
CVE-2020-7324

Improper Access Control vulnerability in McAfee MVISION Endpoint prior to 20.9 Update allows local users to bypass security mechanisms and deny acces…

Fix: 20.9+
Fix from $1,600 2020-09-09
Modbus Driver Suite HIGH 7.8
CVE-2020-7523

Improper Privilege Management vulnerability exists in Schneider Electric Modbus Serial Driver (see security notification for versions) which could ca…

Fix: 2.20_ie_30 / 3.20_ie_30+
Fix from $1,950 2020-08-31
Security Guardium Insights HIGH 7.2
CVE-2020-4603

IBM Security Guardium Insights 2.0.1 performs an operation at a privilege level that is higher than the minimum level required, which creates new wea…

Patch available
Fix from $1,950 2020-08-27
Big Ip Access Policy Manager MEDIUM 6.8
CVE-2020-5916

In BIG-IP versions 15.1.0-15.1.0.4 and 15.0.0-15.0.1.3 the Certificate Administrator user role and higher privileged roles can perform arbitrary file…

Fix: 15.0.1.4 / 15.1.0.5+
Fix from $1,600 2020-08-26
Aleos HIGH 7.8
CVE-2019-11847

An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user can escalate to root via the co…

Fix: 4.4.9 / 4.9.4+
Fix from $1,950 2020-08-21
Urx MEDIUM 6.8
CVE-2020-10290

Universal Robots controller execute URCaps (zip files containing Java-powered applications) without any permission restrictions and a wide API that p…

Mitigation only
Fix from $1,600 2020-08-21
Total Protection MEDIUM 6.9
CVE-2020-7310

Privilege Escalation vulnerability in the installer in McAfee McAfee Total Protection (MTP) trial prior to 4.0.161.1 allows local users to change fil…

Fix: 4.0.161.1+
Fix from $1,600 2020-08-21
Zulip Server MEDIUM 5.4
CVE-2020-14194

Zulip Server before 2.1.5 allows reverse tabnapping via a topic header link.

Fix: 2.1.5+
Fix from $1,600 2020-08-21
Zulip Server HIGH 7.5
CVE-2020-14215

Zulip Server before 2.1.5 has Incorrect Access Control because 0198_preregistrationuser_invited_as adds the administrator role to invitations.

Fix: 2.1.5+
Fix from $1,950 2020-08-21
Ubuntu Linux HIGH 7.8
CVE-2020-15862

Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as …

Fix: 5.8.1+
Fix from $1,950 2020-08-20
Nodebb CRITICAL 9.9
CVE-2020-15149

NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user…

Fix: 1.14.3+
Fix from $2,300 2020-08-20
Enterprise Search HIGH 8.8
CVE-2020-7018

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, t…

Fix: 7.9.0+
Fix from $1,950 2020-08-18
Elasticsearch MEDIUM 6.5
CVE-2020-7019

In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs …

Fix: 6.8.12 / 7.9.0+
Fix from $1,600 2020-08-18
Windows 10 HIGH 7.0
CVE-2020-1488

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in acc…

Patch available
Fix from $1,950 2020-08-17