Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.1
CVE-2024-30150
HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure a…
Dryice Mycloud
Mitigation only
HIGH 8.8
CVE-2024-12284EPSS 13%
Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
Netscaler Agent
13.1-56.18 / 14.1-38.53+
HIGH 7.8
CVE-2025-0893
Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.
No fix yet
HIGH 8.8
CVE-2024-57778
An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status code…
No fix yet
HIGH 7.8
CVE-2025-0327
CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit
trail data and the other acting as server m…
Mitigation only
CRITICAL 9.8
CVE-2024-57602
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
Easyappointments
No fix yet
HIGH 7.3
CVE-2024-21966
A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resulting in arb…
Mitigation only
MEDIUM 6.5
CVE-2025-25202
Ash Authentication is an authentication framework for Elixir applications. Applications which have been bootstrapped by the igniter installer present…
Ash Authentication
4.4.9+
CRITICAL 9.8
CVE-2025-0180
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. This is due to the plugin not…
Mitigation only
HIGH 8.8
CVE-2025-23093
The Platform component of Mitel OpenScape 4000 and OpenScape 4000 Manager through V10 R1.54.1 and V11 through R0.22.1 could allow an authenticated at…
Mitigation only
MEDIUM 5.5
CVE-2025-24805
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security ass…
Mobile Security Framework
4.3.1+
HIGH 7.8
CVE-2024-11467
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue…
Mitigation only
HIGH 8.0
CVE-2024-47770
Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premise…
Wazuh
4.9.1+
HIGH 8.8
CVE-2024-13343
The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new…
Woocommerce Customers Manager
31.4+
MEDIUM 5.4
CVE-2025-22220
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network acces…
Aria Operations For Logs
8.18.3+
MEDIUM 5.5
CVE-2025-23007
A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leadi…
Mitigation only
HIGH 7.8
CVE-2025-0834
Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate priv…
Mitigation only
MEDIUM 5.5
CVE-2021-3978
When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided s…
Octorpki
1.4.2+
HIGH 7.1
CVE-2025-0651
Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation.
User with a low system privileges can create a …
Warp
2024.12.492.0+
HIGH 8.6
CVE-2024-11218
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when buil…
Patch available
HIGH 7.8
CVE-2024-49742
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a mis…
Android
Mitigation only
MEDIUM 5.3
CVE-2025-23208
zot is a production-ready vendor-neutral OCI image registry. The group data stored for users in the boltdb database (meta.db) is an append-list so gr…
Zot
2.1.2+
HIGH 7.8
CVE-2018-9375
In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy…
Android
Mitigation only
HIGH 8.7
CVE-2024-55954
OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Adm…
Mitigation only
CRITICAL 9.8
CVE-2024-9636
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin …
Mitigation only
HIGH 7.8
CVE-2025-21360
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
Autoupdate
4.76+
HIGH 7.5
CVE-2025-21343
Windows Web Threat Defense User Service Information Disclosure Vulnerability
Windows 11 22h2
10.0.22621.4751 / 10.0.22631.4751+
HIGH 7.8
CVE-2025-21287
Windows Installer Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
HIGH 8.8
CVE-2024-12398
An improper privilege management vulnerability in the web management interface of the Zyxel WBE530 firmware versions through 7.00(ACLE.3) and WBE660S…
Nwa50ax Firmware
7.10+
HIGH 7.8
CVE-2024-11128
A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic library injection (DYLD injec…
Virus Scanner
3.18+