Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.8 CVE-2025-64489 SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.7 and prior, 8.0.0-beta.1 thr… Suitecrm 7.14.8 / 8.9.1+ Fix from $1,9502025-11-08 MEDIUM 5.3 CVE-2025-64436 KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the virt-handler service account, su… Kubevirt after 1.6.1 Fix from $1,6002025-11-07 CRITICAL 9.0 CVE-2025-64338 ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collecti… Clipbucket 5.5.2-157+ Fix from $2,3002025-11-07 MEDIUM 5.4 CVE-2025-64336 ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is vulnerable to stored Cross-sit… Clipbucket 5.5.2-147+ Fix from $1,6002025-11-07 HIGH 8.8 CVE-2025-12485 Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another … Devolutions Server 2025.2.17.0 / 2025.3.6.0+ Fix from $1,9502025-11-06 HIGH 7.2 CVE-2025-46364 Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerability to gain… Cloudlink 8.1.1+ Fix from $1,9502025-11-05 MEDIUM 5.8 CVE-2025-12683 The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a N… Mitigation only Fix from $1,6002025-11-04 HIGH 7.2 CVE-2024-13997 Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrat… Nagios Xi 2024+ Fix from $1,9502025-11-03 CRITICAL 9.8 CVE-2025-8900 The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. This is due to the plugin allowi… Mitigation only Fix from $2,3002025-11-03 CRITICAL 9.8 CVE-2025-8489EPSS 9% The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vulnerable to privilege escalat… Mitigation only Fix from $2,3002025-10-31 HIGH 7.8 CVE-2025-48982 This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a m… Veeam Agent For Windows 6.3.2.1302+ Fix from $1,9502025-10-31 HIGH 7.2 CVE-2024-14009 Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an… Nagios Xi 2024+ Fix from $1,9502025-10-30 HIGH 8.8 CVE-2024-14004 Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenti… Nagios Xi 2024+ Fix from $1,9502025-10-30 HIGH 8.8 CVE-2025-61429 An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request. No fix yet Fix from $1,9502025-10-29 CRITICAL 9.8 CVE-2025-12424 Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . Blu Ic2 Firmware 1.20+ Fix from $2,3002025-10-28 HIGH 7.8 CVE-2025-12425 Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . Blu Ic2 Firmware 1.20+ Fix from $1,9502025-10-28 HIGH 7.5 CVE-2025-1037 By making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user level shell commands can enabl… Mitigation only Fix from $1,9502025-10-28 MEDIUM 5.3 CVE-2021-43768 In Malwarebytes For Teams v.1.0.990 and before and fixed in v.1.0.1003 and later a privilege escalation can occur via the COM interface running in mb… Mitigation only Fix from $1,6002025-10-24 HIGH 8.1 CVE-2025-11086 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up … Mitigation only Fix from $1,9502025-10-22 MEDIUM 6.0 CVE-2025-62592 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7… Vm Virtualbox Mitigation only Fix from $1,6002025-10-21 MEDIUM 6.5 CVE-2025-61759 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7… Vm Virtualbox Mitigation only Fix from $1,6002025-10-21 CRITICAL 9.8 CVE-2025-7851 An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways. Fr307 M2 Firmware 1.0.3 / 1.1.4+ Fix from $2,3002025-10-21 HIGH 7.3 CVE-2025-6042 The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation in al… Mitigation only Fix from $1,9502025-10-15 MEDIUM 6.5 CVE-2025-56747 Creativeitem Academy LMS up to and including 5.13 contains a privilege escalation vulnerability in the Api_instructor controller where regular authen… Academy Lms after 5.13 Fix from $1,6002025-10-14 HIGH 7.8 CVE-2025-9068 A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx.… Factorytalk Linx 6.50+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-9067 A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credent… Factorytalk Linx 6.50+ Fix from $1,9502025-10-14 CRITICAL 9.8 CVE-2025-11533 The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. This is due to the process_reg… Mitigation only Fix from $2,3002025-10-11 MEDIUM 6.5 CVE-2025-61152 python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A malicious act… No fix yet Fix from $1,6002025-10-10 CRITICAL 9.8 CVE-2025-59247 Azure PlayFab Elevation of Privilege Vulnerability Azure Playfab No fix yet Fix from $2,3002025-10-09 HIGH 8.8 CVE-2025-11561 A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, t… Mitigation only Fix from $1,9502025-10-09