Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2025-4601EPSS 6%
The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is…
Mitigation only
HIGH 7.8
CVE-2025-27811
A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a local attacker to escalate thei…
Synapse 4
after 4.0.86.2502180127
HIGH 7.8
CVE-2025-26396
The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vul…
Mitigation only
HIGH 8.8
CVE-2025-0358
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework th…
Axis Os
12.4.0+
HIGH 7.8
CVE-2025-4636
Due to excessive privileges granted to the web user running the airpointer web platform, a malicious actor that gains control of the this user would …
Mitigation only
HIGH 8.8
CVE-2024-51392
An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the getPDF.php component
Mitigation only
HIGH 7.8
CVE-2024-40462
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE component
Innovation
No fix yet
HIGH 7.2
CVE-2024-41199
An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a cr…
Innovation
No fix yet
HIGH 7.8
CVE-2024-40458
An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modification of TCP packets.
Innovation
No fix yet
HIGH 7.8
CVE-2024-40459
An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the application manager function
Innovation
No fix yet
HIGH 7.8
CVE-2024-40460
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE
Innovation
No fix yet
HIGH 7.8
CVE-2024-40461
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE component
Innovation
No fix yet
HIGH 7.2
CVE-2025-44040
An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash function. Authentication decisions …
Orangehrm
Mitigation only
MEDIUM 5.5
CVE-2025-24183
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local user may …
macOS
13.7.3 / 14.7.3+
CRITICAL 9.8
CVE-2025-30475
Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthenticated attacker with remote…
Insightiq
6.0.0+
HIGH 7.8
CVE-2025-29976
Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.
Sharepoint Server
16.0.18526.20286+
HIGH 7.0
CVE-2025-27468
Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 7.8
CVE-2025-31222
A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, macOS Sonoma 14.7.6, mac…
Ipados
2.5 / 11.5+
HIGH 7.8
CVE-2025-24258
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.6, macOS Ventura 13.7.6.…
macOS
13.7.6 / 14.7.6+
HIGH 8.7
CVE-2024-8100
On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on C…
Mitigation only
CRITICAL 10.0
CVE-2025-0505
On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the Cloud…
Mitigation only
HIGH 8.8
CVE-2025-4335
The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.7.1. This is …
Mitigation only
HIGH 8.8
CVE-2025-3852
The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions 2.0.0 to 2.6.0. This is due to …
Mitigation only
HIGH 8.7
CVE-2025-47420
266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49.
Mitigation only
HIGH 7.3
CVE-2025-3438
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up …
Mstore Api
4.17.5+
CRITICAL 9.0
CVE-2025-32974
XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights an…
Xwiki
15.10.8 / 16.2.0+
CRITICAL 9.8
CVE-2025-25962
An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function
Mitigation only
HIGH 7.1
CVE-2025-4085
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate priv…
Firefox
138.0+
HIGH 7.8
CVE-2025-3224
A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate…
Desktop
4.41.0+
MEDIUM 6.5
CVE-2025-46576
There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privi…
Zxcloud Goldendb
Mitigation only