Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2025-6759
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS
Virtual Apps And Desktops
2503+
HIGH 7.8
CVE-2025-43019
A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbit…
Support Assistant
Mitigation only
HIGH 7.8
CVE-2025-24006
A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.
Charx Sec 3000 Firmware
1.7.3+
HIGH 7.1
CVE-2025-36630
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system file…
Nessus
10.8.5+
CRITICAL 9.8
CVE-2025-6934EPSS 25%
The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vul…
Mitigation only
HIGH 8.2
CVE-2025-53003
The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without s…
Patch available
MEDIUM 6.5
CVE-2025-45737
An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafted IOCTL c…
Neacsafe64
1.0.0.8+
MEDIUM 6.5
CVE-2025-52555
Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged…
Patch available
HIGH 8.7
CVE-2025-37101
A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an a…
Mitigation only
CRITICAL 9.8
CVE-2025-4334
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to ins…
Memberhero
after 6.3
CRITICAL 10.0
CVE-2025-20282EPSS 27%
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an aff…
Identity Services Engine
Mitigation only
HIGH 8.1
CVE-2025-39202
A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and over…
Microscada X Sys600
10.7+
HIGH 8.4
CVE-2023-50450
An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated privileges.
Visor Vision Sensors Firmware
2.10.0.2+
HIGH 7.8
CVE-2025-49156
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installation…
Apex One
14.0.0.14002 / 14.0.14492+
HIGH 7.8
CVE-2025-49157
A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected in…
Apex One
14.0.0.14002 / 14.0.14492+
HIGH 7.8
CVE-2025-4879
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
Workspace
2402 / 2409+
HIGH 7.8
CVE-2025-0320
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows
Secure Access Client
25.5.1.15+
HIGH 7.4
CVE-2025-6177
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code e…
Chrome Os
Mitigation only
HIGH 8.5
CVE-2025-5689
A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to…
Authd
0.5.4+
HIGH 7.8
CVE-2025-36633
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files …
Nessus Agent
10.8.5+
HIGH 7.8
CVE-2025-36631
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files…
Nessus Agent
10.8.5+
HIGH 8.8
CVE-2025-5491
Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a custom protocol to invoke inter…
Mitigation only
HIGH 7.8
CVE-2025-5687
A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root.
*This bug only affects Mozilla VPN on macOS. Other op…
Vpn
2.28.0+
HIGH 8.8
CVE-2025-4315
The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.…
Cubewp
1.1.24+
HIGH 8.8
CVE-2025-47713
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…
Cloudstack
4.19.3.0 / 4.20.1.0+
HIGH 8.8
CVE-2025-47849
A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d…
Cloudstack
4.19.3.0 / 4.20.1.0+
HIGH 7.8
CVE-2025-47955
Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 8.4
CVE-2025-33067
Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
HIGH 7.2
CVE-2025-22254
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS …
Fortios
6.4.16 / 7.0.17+
HIGH 8.6
CVE-2025-4681
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abuse.This issue affects upKeepe…
Mitigation only