Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Control M\/agent HIGH 8.8
CVE-2019-19216

BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.

No fix yet
Fix from $1,950 2020-04-30
Jnr1010 Firmware HIGH 8.8
CVE-2018-21226

Certain NETGEAR devices are affected by authentication bypass. This affects JNR1010v2 before 1.1.0.48, JWNR2010v5 before 1.1.0.48, WNR1000v4 before 1…

Fix: 1.1.0.48+
Fix from $1,950 2020-04-28
Import Export Wordpress Users HIGH 8.8
CVE-2020-12074

The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.

Fix: 1.3.9+
Fix from $1,950 2020-04-23
Wac505 Firmware HIGH 8.8
CVE-2018-21124

NETGEAR WAC510 devices before 5.0.0.17 are affected by privilege escalation.

Fix: 5.0.0.17+
Fix from $1,950 2020-04-22
800xa Base System HIGH 7.8
CVE-2020-8474

Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system function…

Fix: after 6.0.0
Fix from $1,950 2020-04-22
M4300 28g Firmware HIGH 7.8
CVE-2017-18837

Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G…

Fix: 12.0.2.15+
Fix from $1,950 2020-04-20
M4300 28g Firmware HIGH 7.8
CVE-2017-18830

Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G…

Fix: 12.0.2.15+
Fix from $1,950 2020-04-20
M4300 28g Firmware HIGH 7.8
CVE-2017-18826

Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G…

Fix: 12.0.2.15+
Fix from $1,950 2020-04-20
M4300 28g Firmware HIGH 7.8
CVE-2017-18829

Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G…

Fix: 12.0.2.15+
Fix from $1,950 2020-04-20
M4300 28g Firmware HIGH 7.8
CVE-2017-18822

Certain NETGEAR devices are affected by vertical privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G…

Fix: 12.0.2.15+
Fix from $1,950 2020-04-20
M4300 28g Firmware HIGH 7.8
CVE-2017-18838

Certain NETGEAR devices are affected by privilege escalation. This affects M4300-28G before 12.0.2.15, M4300-52G before 12.0.2.15, M4300-28G-POE+ bef…

Fix: 12.0.2.15+
Fix from $1,950 2020-04-20
Ucs Director CRITICAL 9.8
CVE-2020-3243EPSS 88%

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth…

Fix: after 3.7.3.0
Fix from $2,300 2020-04-15
Ucs Director CRITICAL 9.8
CVE-2020-3250EPSS 60%

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass auth…

Fix: after 3.7.3.0
Fix from $2,300 2020-04-15
Z Cron CRITICAL 9.8
CVE-2020-11799

Z-Cron 5.6 Build 04 allows an unprivileged attacker to elevate privileges by modifying a privileged user's task. This can also affect all users who a…

No fix yet
Fix from $2,300 2020-04-15
Cimplicity MEDIUM 6.7
CVE-2020-6992

A local privilege escalation vulnerability has been identified in the GE Digital CIMPLICITY HMI/SCADA product v10.0 and prior. If exploited, this vul…

Fix: after 10.0
Fix from $1,600 2020-04-15
Windows 10 HIGH 7.8
CVE-2020-1014

An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Win…

Patch available
Fix from $1,950 2020-04-15
Onedrive MEDIUM 5.5
CVE-2020-0935

An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for…

Patch available
Fix from $1,600 2020-04-15
Endpoint Security HIGH 7.8
CVE-2020-7259

Exploitation of Privilege/Trust vulnerability in file in McAfee Endpoint Security (ENS) Prior to 10.7.0 February 2020 Update allows local users to by…

Mitigation only
Fix from $1,950 2020-04-15
Endpoint Security MEDIUM 5.5
CVE-2020-7273

Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endpoint Security (ENS) for Windo…

Mitigation only
Fix from $1,600 2020-04-15
Endpoint Security HIGH 7.8
CVE-2020-7274

Privilege escalation vulnerability in McTray.exe in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users t…

Mitigation only
Fix from $1,950 2020-04-15
Endpoint Security MEDIUM 6.3
CVE-2020-7257

Privilege escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows local users to cause the…

Mitigation only
Fix from $1,600 2020-04-15
Vantage HIGH 7.8
CVE-2020-8327

A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior…

Fix: 10.2003.10.0+
Fix from $1,950 2020-04-14
Adaptive Extensions HIGH 7.2
CVE-2020-6236

SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership a…

Mitigation only
Fix from $1,950 2020-04-14
Call Recording HIGH 8.8
CVE-2019-18822

A privilege escalation vulnerability in ZOOM Call Recording 6.3.1 allows its user account (i.e., the account under which the program runs - by defaul…

No fix yet
Fix from $1,950 2020-04-14
Mbconnect24 HIGH 7.8
CVE-2020-10384

An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. There is a local privilege escal…

Fix: after 2.6.1
Fix from $1,950 2020-04-14
Provide Ftp Server CRITICAL 9.8
CVE-2020-11708

An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetUserInfo messages parameter be…

Fix: after 13.1
Fix from $2,300 2020-04-12
Traps HIGH 7.1
CVE-2020-1991

An insecure temporary file vulnerability in Palo Alto Networks Traps allows a local authenticated Windows user to escalate privileges or overwrite sy…

Fix: 5.0.8 / 6.1.4+
Fix from $1,950 2020-04-08
Globalprotect HIGH 7.8
CVE-2020-1989

An incorrect privilege assignment vulnerability when writing application-specific files in the Palo Alto Networks Global Protect Agent for Linux on A…

Fix: 5.0.8 / 5.1.1+
Fix from $1,950 2020-04-08
Microk8s HIGH 7.8
CVE-2019-15789

Privilege escalation vulnerability in MicroK8s allows a low privilege user with local access to obtain root access to the host by provisioning a priv…

Fix: 1.15.3+
Fix from $1,950 2020-04-08
Mh Wikibot MEDIUM 6.5
CVE-2020-5302

MH-WikiBot (an IRC Bot for interacting with the Miraheze API), had a bug that allowed any unprivileged user to access the steward commands on the IRC…

Fix: 2020-04-06+
Fix from $1,600 2020-04-07