Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
MEDIUM 6.5 CVE-2025-7044 An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged attacker can intercept a user… Maas 3.3.11 / 3.4.9+ Fix from $1,6002025-12-03 CRITICAL 9.8 CVE-2025-13542 The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlm… Mitigation only Fix from $2,3002025-12-02 MEDIUM 6.8 CVE-2025-59705 Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker to Escalate Privileges by en… Nshield 5c Firmware 13.6.12 / 13.9.0+ Fix from $1,6002025-12-02 HIGH 7.2 CVE-2025-59697 Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker to escalate privileges by ed… Nshield 5c Firmware 13.6.12 / 13.9.0+ Fix from $1,9502025-12-02 CRITICAL 9.8 CVE-2025-59693 The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allows a physically proximate atta… Nshield 5c Firmware 13.6.12 / 13.9.0+ Fix from $2,3002025-12-02 HIGH 8.8 CVE-2025-13534 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi… Wsdesk 3.3.3+ Fix from $1,9502025-12-02 MEDIUM 5.4 CVE-2025-65621 Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's sessio… Snipe It 8.3.4+ Fix from $1,6002025-12-01 CRITICAL 9.1 CVE-2025-13787 A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the compo… Zentao 21.7.7+ Fix from $2,3002025-11-30 MEDIUM 5.4 CVE-2025-59790 Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommende… Kvrocks 2.14.0+ Fix from $1,6002025-11-28 CRITICAL 9.8 CVE-2025-13675 The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.… Mitigation only Fix from $2,3002025-11-27 HIGH 8.8 CVE-2025-13680 The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the plugin allowing… Mitigation only Fix from $1,9502025-11-27 CRITICAL 9.8 CVE-2025-13540 The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the 'tiare_… Mitigation only Fix from $2,3002025-11-27 CRITICAL 9.8 CVE-2025-13538 The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the 'finda… Mitigation only Fix from $2,3002025-11-27 HIGH 7.5 CVE-2025-66314 Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Properly Constrained by ACLs.This i… Mitigation only Fix from $1,9502025-11-27 CRITICAL 9.3 CVE-2025-66266 The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control. A local attacker can replace… Mitigation only Fix from $2,3002025-11-26 MEDIUM 6.9 CVE-2025-66265 CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all authenticated users. This allo… Mitigation only Fix from $1,6002025-11-26 HIGH 7.8 CVE-2025-33188 NVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware controls. A successful exploit of t… Dgx Os Mitigation only Fix from $1,9502025-11-25 HIGH 7.8 CVE-2025-33187 NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areas. A succe… Dgx Os Mitigation only Fix from $1,9502025-11-25 CRITICAL 9.8 CVE-2025-13559 The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'edukart_p… Mitigation only Fix from $2,3002025-11-25 MEDIUM 6.0 CVE-2025-54821 An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS… Fortiproxy 1.6.1 / 7.6.4+ Fix from $1,6002025-11-18 CRITICAL 9.1 CVE-2025-40548 A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. … Serv U 15.5.3+ Fix from $2,3002025-11-18 HIGH 8.8 CVE-2025-11923 The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalation. This is due to the plugin… Mitigation only Fix from $1,9502025-11-13 HIGH 7.8 CVE-2025-59514 Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 8.8 CVE-2025-24838 Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalat… Computing Improvement Program 2.4.11001+ Fix from $1,9502025-11-11 MEDIUM 6.5 CVE-2025-24863 Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an informa… Computing Improvement Program 2.4.11001+ Fix from $1,6002025-11-11 HIGH 8.8 CVE-2025-11168 The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5. This is due to plugin not p… Mitigation only Fix from $1,9502025-11-11 CRITICAL 9.8 CVE-2025-11457 The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in versions 0.9… Mitigation only Fix from $2,3002025-11-11 HIGH 7.8 CVE-2025-64507 Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment wher… Incus 6.0.6 / 6.19.0+ Fix from $1,9502025-11-10 HIGH 7.5 CVE-2025-12726 Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer … Chrome 142.0.7444.134+ Fix from $1,9502025-11-10 HIGH 7.7 CVE-2025-12405 An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Looker Studio user with report v… Mitigation only Fix from $1,9502025-11-10