Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.6
CVE-2023-32196
A vulnerability has been identified whereby privilege escalation checks are not properly enforced for RoleTemplateobjects when external=true, which i…
Mitigation only
HIGH 7.2
CVE-2023-32194
A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject…
Mitigation only
HIGH 7.8
CVE-2024-9002
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized
access, loss of confidentiality, integrity, and availabilit…
Mitigation only
MEDIUM 6.5
CVE-2024-22068
Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 64 bit allows Functionality By…
Zxr10 1800 2s Firmware
6.00.10+
CRITICAL 9.8
CVE-2024-9518
The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the …
Userplus
after 2.0
MEDIUM 6.7
CVE-2024-38818
VMware NSX contains a local privilege escalation vulnerability.
An authenticated malicious actor may exploit this vulnerability to obtain permissio…
Mitigation only
CRITICAL 9.8
CVE-2024-3057
A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.
Mitigation only
MEDIUM 6.5
CVE-2024-45919
A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and…
Solvait
No fix yet
MEDIUM 5.9
CVE-2024-44439
An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System v.1.9.1 allows a remote…
No fix yet
CRITICAL 9.8
CVE-2024-44097
According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the se…
Nest Doorbell \(battery\) Firmware
1.73c+
CRITICAL 9.8
CVE-2024-9265
The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due …
Echo Rss Feed Post Generator
5.4.7+
HIGH 8.4
CVE-2024-28813
An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activa…
Hit 7300 Firmware
Mitigation only
HIGH 7.6
CVE-2024-46549
An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices …
Mitigation only
HIGH 7.5
CVE-2024-22893
OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain…
Openslides
Mitigation only
HIGH 8.8
CVE-2024-45373
Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.
Progauge Maglink Lx Console Firmware
after 4.17.9e
MEDIUM 6.6
CVE-2024-44540
Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging P…
Mitigation only
MEDIUM 6.6
CVE-2024-39342
Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Sec…
Mitigation only
HIGH 7.2
CVE-2024-0003
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing…
Purity\/\/fa
after 6.4.10
CRITICAL 9.8
CVE-2024-34331
A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS inst…
Mitigation only
HIGH 7.6
CVE-2024-41228
A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write a…
Mitigation only
CRITICAL 9.8
CVE-2024-8853
The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on t…
Webo Facto
1.41+
MEDIUM 6.5
CVE-2024-46999
Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants …
Zitadel
2.54.10 / 2.55.8+
HIGH 7.5
CVE-2024-47000
Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work correctly with service accounts. D…
Zitadel
2.54.10 / 2.55.8+
HIGH 7.3
CVE-2024-45752
logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus service, in…
Logiops
after 0.3.4
MEDIUM 5.3
CVE-2024-46989
spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple cav…
Spicedb
1.35.3+
CRITICAL 9.9
CVE-2024-45496
A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During…
Mitigation only
MEDIUM 5.5
CVE-2024-44147
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. An app may gain unauthorized access to Local…
Ipados
18.0+
HIGH 7.8
CVE-2024-40861
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to gain root privileges.
macOS
15.0+
HIGH 7.6
CVE-2024-42798
An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Managem…
Music Management System
No fix yet
HIGH 8.8
CVE-2024-6482
The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to a…
Login With Phone Number
1.7.50+