Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Inncom Inncontrol Firmware HIGH 7.8
CVE-2020-6968

Honeywell INNCOM INNControl 3 allows workstation users to escalate application user privileges through the modification of local configuration files.

Fix: after 3.21
Fix from $1,950 2020-02-20
Data Center Network Manager HIGH 8.8
CVE-2020-3112

A vulnerability in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to elevate privile…

Fix: 11.3+
Fix from $1,950 2020-02-19
Change And Configuration Management Database CRITICAL 9.8
CVE-2013-3323

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to …

Mitigation only
Fix from $2,300 2020-02-18
Prestashop CRITICAL 9.8
CVE-2013-6295

PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module

No fix yet
Fix from $2,300 2020-02-18
Articlefr CRITICAL 9.8
CVE-2014-4170EPSS 14%

A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script,…

Fix: after 3.0.4
Fix from $2,300 2020-02-13
Windows 10 HIGH 7.8
CVE-2020-0686

An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of…

Patch available
Fix from $1,950 2020-02-11
Openshift Container Platform HIGH 7.0
CVE-2020-1708

It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers mod…

Mitigation only
Fix from $1,950 2020-02-07
Eyesofnetwork HIGH 7.8
CVE-2020-8655 KEVEPSS 60%

An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to…

Mitigation only
Fix from $1,950 2020-02-07
Dv Ip Express Firmware CRITICAL 9.8
CVE-2015-2909

Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures log…

No fix yet
Fix from $2,300 2020-02-06
Ubuntu Linux HIGH 7.4
CVE-2016-9928

MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity …

Fix: 1.0.4+
Fix from $1,950 2020-02-06
Fortimanager CRITICAL 9.8
CVE-2015-3613

A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page

Fix: after 5.2.1
Fix from $2,300 2020-02-04
J Businessdirectory MEDIUM 6.5
CVE-2020-5182

The J-BusinessDirectory extension before 5.2.9 for Joomla! allows Reverse Tabnabbing. In some configurations, the link to the business website can be…

Fix: 5.2.9+
Fix from $1,600 2020-02-03
Latitude E6430 Firmware HIGH 7.8
CVE-2015-0949

The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver. 01.09, and possi…

Mitigation only
Fix from $1,950 2020-01-30
Antivirus MEDIUM 5.5
CVE-2020-8092

A privilege escalation vulnerability in BDLDaemon as used in Bitdefender Antivirus for Mac allows a local attacker to obtain authentication tokens fo…

Fix: 8.0.0+
Fix from $1,600 2020-01-30
GitLab HIGH 8.8
CVE-2013-4583

The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and git…

Fix: 1.7.8 / 5.4.2+
Fix from $1,950 2020-01-28
GitLab HIGH 8.8
CVE-2019-5468

An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a bloc…

Fix: 11.11.6 / 12.0.4+
Fix from $1,950 2020-01-28
GitLab HIGH 7.5
CVE-2019-5472

An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic commen…

Fix: 11.11.6 / 12.0.4+
Fix from $1,950 2020-01-28
Tc Runtimes HIGH 7.0
CVE-2019-11288

In Pivotal tc Server, 3.x versions prior to 3.2.19 and 4.x versions prior to 4.0.10, and Pivotal tc Runtimes, 7.x versions prior to 7.0.99.B, 8.x ver…

Fix: 3.2.19 / 4.0.10+
Fix from $1,950 2020-01-27
Sd Wan Firmware HIGH 8.8
CVE-2020-3115

A vulnerability in the CLI of the Cisco SD-WAN Solution vManage software could allow an authenticated, local attacker to elevate privileges to root-l…

Mitigation only
Fix from $1,950 2020-01-26
Windows 10 MEDIUM 5.5
CVE-2019-1454

An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile…

Patch available
Fix from $1,600 2020-01-24
Dynamics 365 MEDIUM 6.5
CVE-2018-8654

An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation of Privilege Vulnerability'.

Patch available
Fix from $1,600 2020-01-24
Soapbox HIGH 7.8
CVE-2012-6302

Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox.

Fix: after 0.3.1
Fix from $1,950 2020-01-24
Xenserver HIGH 7.8
CVE-2012-4606

Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vu…

Mitigation only
Fix from $1,950 2020-01-23
Admin By Request HIGH 7.8
CVE-2019-17202

FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to elevate to Administrator privil…

Fix: 6.2.0.0+
Fix from $1,950 2020-01-23
Apt Cacher Ng MEDIUM 5.5
CVE-2019-18899

The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local…

Fix: 3.1-lp151.3.3.1+
Fix from $1,600 2020-01-23
Splunk HIGH 7.8
CVE-2013-6773

Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges

Fix: 5.0.3+
Fix from $1,950 2020-01-23
Galaxy Gear Firmware HIGH 7.5
CVE-2018-16270

Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged pro…

No fix yet
Fix from $1,950 2020-01-22
Galaxy Gear Firmware MEDIUM 6.5
CVE-2018-16271

The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user'…

No fix yet
Fix from $1,600 2020-01-22
Galaxy Gear Firmware CRITICAL 9.8
CVE-2018-16272

The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack …

No fix yet
Fix from $2,300 2020-01-22
Tizen HIGH 8.8
CVE-2018-16262

The pkgmgr system service in Tizen allows an unprivileged process to perform package management actions, due to improper D-Bus security policy config…

Mitigation only
Fix from $1,950 2020-01-22