Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
MEDIUM 6.6 CVE-2023-32196 A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which i… Mitigation only Fix from $1,6002024-10-16 HIGH 7.2 CVE-2023-32194 A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject… Mitigation only Fix from $1,9502024-10-16 HIGH 7.8 CVE-2024-9002 CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and availabilit… Mitigation only Fix from $1,9502024-10-11 MEDIUM 6.5 CVE-2024-22068 Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality By… Zxr10 1800 2s Firmware 6.00.10+ Fix from $1,6002024-10-10 CRITICAL 9.8 CVE-2024-9518 The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the … Userplus after 2.0 Fix from $2,3002024-10-10 MEDIUM 6.7 CVE-2024-38818 VMware NSX contains a local privilege escalation vulnerability.  An authenticated malicious actor may exploit this vulnerability to obtain permissio… Mitigation only Fix from $1,6002024-10-09 CRITICAL 9.8 CVE-2024-3057 A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation. Mitigation only Fix from $2,3002024-10-08 MEDIUM 6.5 CVE-2024-45919 A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and… Solvait No fix yet Fix from $1,6002024-10-07 MEDIUM 5.9 CVE-2024-44439 An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allows a remote… No fix yet Fix from $1,6002024-10-04 CRITICAL 9.8 CVE-2024-44097 According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the se… Nest Doorbell \(battery\) Firmware 1.73c+ Fix from $2,3002024-10-02 CRITICAL 9.8 CVE-2024-9265 The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due … Echo Rss Feed Post Generator 5.4.7+ Fix from $2,3002024-10-01 HIGH 8.4 CVE-2024-28813 An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activa… Hit 7300 Firmware Mitigation only Fix from $1,9502024-09-30 HIGH 7.6 CVE-2024-46549 An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices … Mitigation only Fix from $1,9502024-09-30 HIGH 7.5 CVE-2024-22893 OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain… Openslides Mitigation only Fix from $1,9502024-09-25 HIGH 8.8 CVE-2024-45373 Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator. Progauge Maglink Lx Console Firmware after 4.17.9e Fix from $1,9502024-09-25 MEDIUM 6.6 CVE-2024-44540 Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging P… Mitigation only Fix from $1,6002024-09-23 MEDIUM 6.6 CVE-2024-39342 Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Sec… Mitigation only Fix from $1,6002024-09-23 HIGH 7.2 CVE-2024-0003 A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing… Purity\/\/fa after 6.4.10 Fix from $1,9502024-09-23 CRITICAL 9.8 CVE-2024-34331 A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS inst… Mitigation only Fix from $2,3002024-09-23 HIGH 7.6 CVE-2024-41228 A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write a… Mitigation only Fix from $1,9502024-09-23 CRITICAL 9.8 CVE-2024-8853 The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on t… Webo Facto 1.41+ Fix from $2,3002024-09-20 MEDIUM 6.5 CVE-2024-46999 Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants … Zitadel 2.54.10 / 2.55.8+ Fix from $1,6002024-09-20 HIGH 7.5 CVE-2024-47000 Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work correctly with service accounts. D… Zitadel 2.54.10 / 2.55.8+ Fix from $1,9502024-09-20 HIGH 7.3 CVE-2024-45752 logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus service, in… Logiops after 0.3.4 Fix from $1,9502024-09-19 MEDIUM 5.3 CVE-2024-46989 spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple cav… Spicedb 1.35.3+ Fix from $1,6002024-09-18 CRITICAL 9.9 CVE-2024-45496 A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During… Mitigation only Fix from $2,3002024-09-17 MEDIUM 5.5 CVE-2024-44147 This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized access to Local… Ipados 18.0+ Fix from $1,6002024-09-17 HIGH 7.8 CVE-2024-40861 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to gain root privileges. macOS 15.0+ Fix from $1,9502024-09-17 HIGH 7.6 CVE-2024-42798 An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Managem… Music Management System No fix yet Fix from $1,9502024-09-16 HIGH 8.8 CVE-2024-6482 The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a… Login With Phone Number 1.7.50+ Fix from $1,9502024-09-14