Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2025-6759 Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS Virtual Apps And Desktops 2503+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-43019 A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbit… Support Assistant Mitigation only Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-24006 A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root. Charx Sec 3000 Firmware 1.7.3+ Fix from $1,9502025-07-08 HIGH 7.1 CVE-2025-36630 In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system file… Nessus 10.8.5+ Fix from $1,9502025-07-02 CRITICAL 9.8 CVE-2025-6934EPSS 25% The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vul… Mitigation only Fix from $2,3002025-07-01 HIGH 8.2 CVE-2025-53003 The Janssen Project is an open-source identity and access management (IAM) platform. Prior to version 1.8.0, the Config API returns results without s… Patch available Fix from $1,9502025-07-01 MEDIUM 6.5 CVE-2025-45737 An issue in NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before v1.0.0.8 allows attackers to escalate privileges via sending crafted IOCTL c… Neacsafe64 1.0.0.8+ Fix from $1,6002025-06-27 MEDIUM 6.5 CVE-2025-52555 Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged… Patch available Fix from $1,6002025-06-26 HIGH 8.7 CVE-2025-37101 A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an a… Mitigation only Fix from $1,9502025-06-26 CRITICAL 9.8 CVE-2025-4334 The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to ins… Memberhero after 6.3 Fix from $2,3002025-06-26 CRITICAL 10.0 CVE-2025-20282EPSS 27% A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an aff… Identity Services Engine Mitigation only Fix from $2,3002025-06-25 HIGH 8.1 CVE-2025-39202 A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and over… Microscada X Sys600 10.7+ Fix from $1,9502025-06-24 HIGH 8.4 CVE-2023-50450 An issue was discovered in Sensopart VISOR Vision Sensors before 2.10.0.2 allows local users to perform unspecified actions with elevated privileges. Visor Vision Sensors Firmware 2.10.0.2+ Fix from $1,9502025-06-23 HIGH 7.8 CVE-2025-49156 A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installation… Apex One 14.0.0.14002 / 14.0.14492+ Fix from $1,9502025-06-17 HIGH 7.8 CVE-2025-49157 A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected in… Apex One 14.0.0.14002 / 14.0.14492+ Fix from $1,9502025-06-17 HIGH 7.8 CVE-2025-4879 Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows Workspace 2402 / 2409+ Fix from $1,9502025-06-17 HIGH 7.8 CVE-2025-0320 Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows Secure Access Client 25.5.1.15+ Fix from $1,9502025-06-17 HIGH 7.4 CVE-2025-6177 Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local attacker to gain root code e… Chrome Os Mitigation only Fix from $1,9502025-06-16 HIGH 8.5 CVE-2025-5689 A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to… Authd 0.5.4+ Fix from $1,9502025-06-16 HIGH 7.8 CVE-2025-36633 In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files … Nessus Agent 10.8.5+ Fix from $1,9502025-06-13 HIGH 7.8 CVE-2025-36631 In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files… Nessus Agent 10.8.5+ Fix from $1,9502025-06-13 HIGH 8.8 CVE-2025-5491 Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a custom protocol to invoke inter… Mitigation only Fix from $1,9502025-06-13 HIGH 7.8 CVE-2025-5687 A vulnerability in Mozilla VPN on macOS allows privilege escalation from a normal user to root. *This bug only affects Mozilla VPN on macOS. Other op… Vpn 2.28.0+ Fix from $1,9502025-06-11 HIGH 8.8 CVE-2025-4315 The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… Cubewp 1.1.24+ Fix from $1,9502025-06-11 HIGH 8.8 CVE-2025-47713 A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d… Cloudstack 4.19.3.0 / 4.20.1.0+ Fix from $1,9502025-06-10 HIGH 8.8 CVE-2025-47849 A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT d… Cloudstack 4.19.3.0 / 4.20.1.0+ Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-47955 Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-06-10 HIGH 8.4 CVE-2025-33067 Improper privilege management in Windows Kernel allows an unauthorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21034 / 10.0.14393.8148+ Fix from $1,9502025-06-10 HIGH 7.2 CVE-2025-22254 An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS … Fortios 6.4.16 / 7.0.17+ Fix from $1,9502025-06-10 HIGH 8.6 CVE-2025-4681 Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abuse.This issue affects upKeepe… Mitigation only Fix from $1,9502025-06-10