Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
CRITICAL 9.8 CVE-2026-22238 The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this… Bluvoyix Mitigation only Fix from $2,3002026-01-14 HIGH 7.8 CVE-2025-37186 A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA) client. Successful exploitat… Mitigation only Fix from $1,9502026-01-13 HIGH 8.8 CVE-2025-36640 A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation o… Mitigation only Fix from $1,9502026-01-13 CRITICAL 9.8 CVE-2025-14736 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is du… Mitigation only Fix from $2,3002026-01-09 HIGH 8.8 CVE-2025-66315 There is a configuration defect vulnerability in the version server of ZTE MF258K Pro products. Due to improper directory permission settings, an att… Mf258k Pro Firmware Mitigation only Fix from $1,9502026-01-09 CRITICAL 9.8 CVE-2026-22043 RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 through 1.0.0-alpha.78, a flawed `deny_only` short-circuit in… Rustfs Mitigation only Fix from $2,3002026-01-08 HIGH 8.6 CVE-2026-22536 The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restricti… Mitigation only Fix from $1,9502026-01-07 HIGH 8.1 CVE-2025-47411EPSS 15% A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows th… Streampipes 0.98.0+ Fix from $1,9502026-01-01 MEDIUM 6.7 CVE-2025-69257 theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.1.1, the application loa… Patch available Fix from $1,6002025-12-30 MEDIUM 5.4 CVE-2025-68697 n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances where the Code node runs in legacy (non-task… N8n 2.0.0+ Fix from $1,6002025-12-26 MEDIUM 6.5 CVE-2025-52599 Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered In… Xnv L6080r Firmware 2.23.01+ Fix from $1,6002025-12-26 HIGH 7.7 CVE-2025-67826 An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antivirus can… K7 Ultimate Security Mitigation only Fix from $1,9502025-12-22 CRITICAL 9.8 CVE-2025-13619 The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUs… Mitigation only Fix from $2,3002025-12-20 CRITICAL 9.8 CVE-2025-58053 Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating any existing account with a s… Galette 1.2.0+ Fix from $2,3002025-12-19 MEDIUM 6.2 CVE-2025-66173 There is a privilege escalation vulnerability in some Hikvision DVR products. Due to the improper implementation of authentication for the serial por… Ds 7104hghi F1 Firmware after 4.30.122_201107 Fix from $1,6002025-12-19 HIGH 8.8 CVE-2023-53908 HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF c… No fix yet Fix from $1,9502025-12-17 HIGH 7.8 CVE-2025-67792 An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate a DriveL… Drivelock 24.1.6 / 24.2.7+ Fix from $1,9502025-12-17 CRITICAL 9.8 CVE-2025-67793 An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" … Drivelock 25.1.6+ Fix from $2,3002025-12-17 CRITICAL 9.9 CVE-2025-67781 An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileg… Drivelock 24.1.6 / 24.2.7+ Fix from $2,3002025-12-17 HIGH 7.8 CVE-2025-14252 An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, re… Mitigation only Fix from $1,9502025-12-16 HIGH 7.8 CVE-2025-43512 A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, mac… macOS 14.8.3 / 15.7.3+ Fix from $1,9502025-12-12 HIGH 7.8 CVE-2025-43320 The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app may be able to bypass launch … macOS 15.7.3+ Fix from $1,9502025-12-12 CRITICAL 9.8 CVE-2025-67727 Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI … Parse Server after 8.5.0 Fix from $2,3002025-12-12 CRITICAL 9.8 CVE-2025-13764 The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16. This is due to the 'WP_CarD… Mitigation only Fix from $2,3002025-12-11 HIGH 8.7 CVE-2025-12952 A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook editor permission are able to … Mitigation only Fix from $1,9502025-12-10 HIGH 7.8 CVE-2025-12381 Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection. A local … Firewall Analyzer Mitigation only Fix from $1,9502025-12-09 MEDIUM 5.5 CVE-2025-66324 Input verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vulnerability may affect app da… Harmonyos No fix yet Fix from $1,6002025-12-08 HIGH 7.6 CVE-2025-13292 A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data and access logs belonging to… Mitigation only Fix from $1,9502025-12-06 MEDIUM 6.2 CVE-2025-55076 A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for mac… Installation Manager No fix yet Fix from $1,6002025-12-03 MEDIUM 6.2 CVE-2025-62686 A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin Alliance Installation Manage… Installation Manager No fix yet Fix from $1,6002025-12-03