Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Textpattern MEDIUM 5.3
CVE-2015-8032

In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.

Patch available
Fix from $1,600 2020-08-14
Fedora HIGH 7.8
CVE-2020-24330

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop t…

Fix: after 0.3.14
Fix from $1,950 2020-08-13
Fedora HIGH 7.8
CVE-2020-24331

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access …

Fix: after 0.3.14
Fix from $1,950 2020-08-13
Data Loss Prevention MEDIUM 6.5
CVE-2020-7305

Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to crea…

Fix: 11.3.28 / 11.4.200+
Fix from $1,600 2020-08-13
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2020-11552EPSS 7%

An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privile…

Fix: after 5.8
Fix from $2,300 2020-08-11
Kotlin HIGH 8.8
CVE-2020-15824

In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege e…

Patch available
Fix from $1,950 2020-08-08
Ram Disk HIGH 7.1
CVE-2020-13522

An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) …

No fix yet
Fix from $1,950 2020-08-04
Skysea Client View HIGH 7.8
CVE-2020-5617

Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify…

Fix: after 15.210.05f
Fix from $1,950 2020-08-04
Trb245 Firmware HIGH 8.8
CVE-2020-5773

Improper Access Control in Teltonika firmware TRB2_R_00.02.04.01 allows a low privileged user to perform unauthorized write operations.

No fix yet
Fix from $1,950 2020-08-03
Pi Hole HIGH 7.8
CVE-2020-14162

An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a passw…

Fix: 5.1+
Fix from $1,950 2020-07-30
Openclinic Ga HIGH 8.8
CVE-2020-14493

A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of a…

Mitigation only
Fix from $1,950 2020-07-29
Creative Cloud CRITICAL 9.8
CVE-2020-9669

Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Successful exploitation could lea…

Fix: after 5.1
Fix from $2,300 2020-07-17
Xarm 5 Lite Firmware HIGH 8.8
CVE-2020-10286

the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to …

Fix: after 1.5.0
Fix from $1,950 2020-07-15
Windows 10 HIGH 7.8
CVE-2020-1431

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in acc…

Patch available
Fix from $1,950 2020-07-14
Windows 10 HIGH 8.8
CVE-2020-1412EPSS 14%

A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Componen…

Patch available
Fix from $1,950 2020-07-14
Azure Storage Explorer HIGH 8.8
CVE-2020-1416EPSS 6%

An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and V…

Fix: 1.47.1 / 15.9.25+
Fix from $1,950 2020-07-14
Opcenter Execution Core HIGH 8.1
CVE-2020-7578

A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Authenticated users…

Fix: 8.2+
Fix from $1,950 2020-07-14
Cmciii Pu 9333e0fb Firmware CRITICAL 9.8
CVE-2020-11956

An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a least privilege violation.

Fix: after 6.17.00
Fix from $2,300 2020-07-14
Zonealarm Extreme Security HIGH 8.8
CVE-2020-6013

ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at ele…

Fix: 15.8.109.18436+
Fix from $1,950 2020-07-06
Total Protection HIGH 8.8
CVE-2020-7283

Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link man…

Fix: 16.0.r26+
Fix from $1,950 2020-07-03
Total Protection MEDIUM 6.3
CVE-2020-7281

Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not…

Fix: 16.0.r26+
Fix from $1,600 2020-07-03
Rgb Driver Firmware MEDIUM 5.5
CVE-2020-15368

AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request …

Mitigation only
Fix from $1,600 2020-06-29
Ubridge MEDIUM 5.5
CVE-2020-14976

GNS3 ubridge through 0.9.18 on macOS, as used in GNS3 server before 2.1.17, allows a local attacker to read arbitrary files because it handles config…

Fix: after 0.9.18
Fix from $1,600 2020-06-23
Mattermost Server HIGH 8.1
CVE-2017-18884

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by using a registered OAuth appli…

Fix: 4.1.2 / 4.2.1+
Fix from $1,950 2020-06-19
Mattermost Server CRITICAL 9.8
CVE-2017-18885

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpo…

Fix: 4.1.2 / 4.2.1+
Fix from $2,300 2020-06-19
Mattermost Server HIGH 7.5
CVE-2019-20886

An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.

Fix: 5.8.0+
Fix from $1,950 2020-06-19
Fusionsphere Openstack HIGH 7.8
CVE-2020-9225

FusionSphere OpenStack 6.5.1 have an improper permissions management vulnerability. The software does not correctly perform a privilege assignment wh…

Mitigation only
Fix from $1,950 2020-06-18
Easergy T300 Firmware HIGH 7.2
CVE-2020-7509

A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacke…

Fix: after 1.5.2
Fix from $1,950 2020-06-16
Pandora Fms CRITICAL 9.8
CVE-2020-13854

Artica Pandora FMS 7.44 allows privilege escalation.

No fix yet
Fix from $2,300 2020-06-11
Gateway HIGH 7.2
CVE-2020-12713

An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.…

Fix: after 4.7.1-0
Fix from $1,950 2020-06-11