Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
CRITICAL 9.1 CVE-2024-30150 HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure a… Dryice Mycloud Mitigation only Fix from $2,3002025-02-25 HIGH 8.8 CVE-2024-12284EPSS 13% Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. Netscaler Agent 13.1-56.18 / 14.1-38.53+ Fix from $1,9502025-02-20 HIGH 7.8 CVE-2025-0893 Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability. No fix yet Fix from $1,9502025-02-19 HIGH 8.8 CVE-2024-57778 An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status code… No fix yet Fix from $1,9502025-02-14 HIGH 7.8 CVE-2025-0327 CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server m… Mitigation only Fix from $1,9502025-02-13 CRITICAL 9.8 CVE-2024-57602 An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file. Easyappointments No fix yet Fix from $2,3002025-02-12 HIGH 7.3 CVE-2024-21966 A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resulting in arb… Mitigation only Fix from $1,9502025-02-11 MEDIUM 6.5 CVE-2025-25202 Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present… Ash Authentication 4.4.9+ Fix from $1,6002025-02-11 CRITICAL 9.8 CVE-2025-0180 The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin not… Mitigation only Fix from $2,3002025-02-11 HIGH 8.8 CVE-2025-23093 The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated at… Mitigation only Fix from $1,9502025-02-06 MEDIUM 5.5 CVE-2025-24805 Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security ass… Mobile Security Framework 4.3.1+ Fix from $1,6002025-02-05 HIGH 7.8 CVE-2024-11467 Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue… Mitigation only Fix from $1,9502025-02-04 HIGH 8.0 CVE-2024-47770 Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premise… Wazuh 4.9.1+ Fix from $1,9502025-02-03 HIGH 8.8 CVE-2024-13343 The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new… Woocommerce Customers Manager 31.4+ Fix from $1,9502025-02-01 MEDIUM 5.4 CVE-2025-22220 VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network acces… Aria Operations For Logs 8.18.3+ Fix from $1,6002025-01-30 MEDIUM 5.5 CVE-2025-23007 A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leadi… Mitigation only Fix from $1,6002025-01-30 HIGH 7.8 CVE-2025-0834 Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate priv… Mitigation only Fix from $1,9502025-01-30 MEDIUM 5.5 CVE-2021-3978 When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided s… Octorpki 1.4.2+ Fix from $1,6002025-01-29 HIGH 7.1 CVE-2025-0651 Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges  can create a … Warp 2024.12.492.0+ Fix from $1,9502025-01-22 HIGH 8.6 CVE-2024-11218 A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when buil… Patch available Fix from $1,9502025-01-22 HIGH 7.8 CVE-2024-49742 In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a mis… Android Mitigation only Fix from $1,9502025-01-21 MEDIUM 5.3 CVE-2025-23208 zot is a production-ready vendor-neutral OCI image registry. The group data stored for users in the boltdb database (meta.db) is an append-list so gr… Zot 2.1.2+ Fix from $1,6002025-01-17 HIGH 7.8 CVE-2018-9375 In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy… Android Mitigation only Fix from $1,9502025-01-17 HIGH 8.7 CVE-2024-55954 OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Adm… Mitigation only Fix from $1,9502025-01-16 CRITICAL 9.8 CVE-2024-9636 The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin … Mitigation only Fix from $2,3002025-01-15 HIGH 7.8 CVE-2025-21360 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability Autoupdate 4.76+ Fix from $1,9502025-01-14 HIGH 7.5 CVE-2025-21343 Windows Web Threat Defense User Service Information Disclosure Vulnerability Windows 11 22h2 10.0.22621.4751 / 10.0.22631.4751+ Fix from $1,9502025-01-14 HIGH 7.8 CVE-2025-21287 Windows Installer Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,9502025-01-14 HIGH 8.8 CVE-2024-12398 An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S… Nwa50ax Firmware 7.10+ Fix from $1,9502025-01-14 HIGH 7.8 CVE-2024-11128 A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injec… Virus Scanner 3.18+ Fix from $1,9502025-01-13