Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.8 CVE-2025-4601EPSS 6% The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is… Mitigation only Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-27811 A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate thei… Synapse 4 after 4.0.86.2502180127 Fix from $1,9502025-06-04 HIGH 7.8 CVE-2025-26396 The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vul… Mitigation only Fix from $1,9502025-06-02 HIGH 8.8 CVE-2025-0358 During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th… Axis Os 12.4.0+ Fix from $1,9502025-06-02 HIGH 7.8 CVE-2025-4636 Due to excessive privileges granted to the web user running the airpointer web platform, a malicious actor that gains control of the this user would … Mitigation only Fix from $1,9502025-05-30 HIGH 8.8 CVE-2024-51392 An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component Mitigation only Fix from $1,9502025-05-29 HIGH 7.8 CVE-2024-40462 An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE component Innovation No fix yet Fix from $1,9502025-05-22 HIGH 7.2 CVE-2024-41199 An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a cr… Innovation No fix yet Fix from $1,9502025-05-22 HIGH 7.8 CVE-2024-40458 An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets. Innovation No fix yet Fix from $1,9502025-05-22 HIGH 7.8 CVE-2024-40459 An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager function Innovation No fix yet Fix from $1,9502025-05-22 HIGH 7.8 CVE-2024-40460 An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE Innovation No fix yet Fix from $1,9502025-05-22 HIGH 7.8 CVE-2024-40461 An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE component Innovation No fix yet Fix from $1,9502025-05-22 HIGH 7.2 CVE-2025-44040 An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions … Orangehrm Mitigation only Fix from $1,9502025-05-21 MEDIUM 5.5 CVE-2025-24183 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local user may … macOS 13.7.3 / 14.7.3+ Fix from $1,6002025-05-19 CRITICAL 9.8 CVE-2025-30475 Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote… Insightiq 6.0.0+ Fix from $2,3002025-05-15 HIGH 7.8 CVE-2025-29976 Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally. Sharepoint Server 16.0.18526.20286+ Fix from $1,9502025-05-13 HIGH 7.0 CVE-2025-27468 Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 HIGH 7.8 CVE-2025-31222 A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, macOS Sonoma 14.7.6, mac… Ipados 2.5 / 11.5+ Fix from $1,9502025-05-12 HIGH 7.8 CVE-2025-24258 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6.… macOS 13.7.6 / 14.7.6+ Fix from $1,9502025-05-12 HIGH 8.7 CVE-2024-8100 On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on C… Mitigation only Fix from $1,9502025-05-08 CRITICAL 10.0 CVE-2025-0505 On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the Cloud… Mitigation only Fix from $2,3002025-05-08 HIGH 8.8 CVE-2025-4335 The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.7.1. This is … Mitigation only Fix from $1,9502025-05-07 HIGH 8.8 CVE-2025-3852 The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to … Mitigation only Fix from $1,9502025-05-07 HIGH 8.7 CVE-2025-47420 266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. Mitigation only Fix from $1,9502025-05-06 HIGH 7.3 CVE-2025-3438 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up … Mstore Api 4.17.5+ Fix from $1,9502025-05-02 CRITICAL 9.0 CVE-2025-32974 XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights an… Xwiki 15.10.8 / 16.2.0+ Fix from $2,3002025-04-30 CRITICAL 9.8 CVE-2025-25962 An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function Mitigation only Fix from $2,3002025-04-29 HIGH 7.1 CVE-2025-4085 An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate priv… Firefox 138.0+ Fix from $1,9502025-04-29 HIGH 7.8 CVE-2025-3224 A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate… Desktop 4.41.0+ Fix from $1,9502025-04-28 MEDIUM 6.5 CVE-2025-46576 There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privi… Zxcloud Goldendb Mitigation only Fix from $1,6002025-04-27