Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.8 CVE-2025-36891 Elevation of privilege Android No fix yet Fix from $1,9502025-09-04 CRITICAL 9.8 CVE-2025-36896 WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-394765106. Android Mitigation only Fix from $2,3002025-09-04 MEDIUM 5.3 CVE-2025-32098 An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insec… Magician after 8.3.0 Fix from $1,6002025-09-02 HIGH 8.1 CVE-2024-46916 Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesyst… Vynamic Security Suite after 4.3.0sr06 Fix from $1,9502025-08-29 MEDIUM 6.6 CVE-2025-55582 D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries such as `dc… Dcs 825l Firmware No fix yet Fix from $1,6002025-08-27 HIGH 7.5 CVE-2025-53105 GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that provides ITIL Service Desk f… Mitigation only Fix from $1,9502025-08-27 HIGH 7.2 CVE-2025-36729 A non-primary administrator user with admin rights to the web interface but without shell access permissions can display configuration of the device … Mitigation only Fix from $1,9502025-08-26 HIGH 8.8 CVE-2025-6366 The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. This is due to the plugin not … Mitigation only Fix from $1,9502025-08-26 HIGH 8.8 CVE-2024-47853 An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with … Mahara 23.04.9 / 24.04.5+ Fix from $1,9502025-08-26 HIGH 8.8 CVE-2025-5931 The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.0.5. This is du… Mitigation only Fix from $1,9502025-08-26 HIGH 8.8 CVE-2025-57760 Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers whe… Langflow 1.5.0+ Fix from $1,9502025-08-25 HIGH 7.3 CVE-2025-55581 D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh script. The scrip… Dcs 825l Firmware after 1.08.01 Fix from $1,9502025-08-22 MEDIUM 5.3 CVE-2025-55627 Insufficient privilege verification in Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 allows authenticat… Mitigation only Fix from $1,6002025-08-22 HIGH 7.8 CVE-2025-50674 An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local au… Openmediavault No fix yet Fix from $1,9502025-08-22 HIGH 8.5 CVE-2025-6182 The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could exploit this behavior to ins… Mitigation only Fix from $1,9502025-08-20 HIGH 8.1 CVE-2025-8309 There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and Supp… Mitigation only Fix from $1,9502025-08-20 MEDIUM 6.7 CVE-2025-8453 CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privileged engi… Mitigation only Fix from $1,6002025-08-20 CRITICAL 9.8 CVE-2025-6758 The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' functi… Mitigation only Fix from $2,3002025-08-19 HIGH 8.8 CVE-2025-8218 The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' paramet… Mitigation only Fix from $1,9502025-08-19 HIGH 8.8 CVE-2025-6080 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in all versions up to, and incl… Mitigation only Fix from $1,9502025-08-16 HIGH 8.8 CVE-2025-49758 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege… Sql Server 2016 13.0.6465.1 / 13.0.7060.1+ Fix from $1,9502025-08-12 CRITICAL 9.8 CVE-2025-8660 Privilege escalation occurs when a user gets access to more resources or functionality than they are normally allowed. Symantec Pgp Encryption No fix yet Fix from $2,3002025-08-11 HIGH 7.2 CVE-2025-54996 OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions … Openbao 2.3.2+ Fix from $1,9502025-08-09 HIGH 7.8 CVE-2025-26513 The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allo… San Host Utilities 8.0+ Fix from $1,9502025-08-07 CRITICAL 9.8 CVE-2025-6994 The Reveal Listing plugin by smartdatasoft for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.3. This is due to … Mitigation only Fix from $2,3002025-08-06 CRITICAL 9.1 CVE-2025-54594 react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml Gi… Patch available Fix from $2,3002025-08-06 HIGH 8.5 CVE-2013-10052 ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured … No fix yet Fix from $1,9502025-08-04 HIGH 8.5 CVE-2012-10022 Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsu… No fix yet Fix from $1,9502025-08-01 HIGH 7.3 CVE-2025-54595 Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged helper tool bundled with the Pe… Patch available Fix from $1,9502025-08-01 CRITICAL 9.8 CVE-2025-5954 The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2… Mitigation only Fix from $2,3002025-08-01