Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.8 CVE-2024-8246 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulner… Buddyforms 2.8.12+ Fix from $1,9502024-09-14 HIGH 7.8 CVE-2024-29779 there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional executi… Android No fix yet Fix from $1,9502024-09-13 CRITICAL 9.1 CVE-2024-7960 The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The v… Pavilion8 6.0+ Fix from $2,3002024-09-12 HIGH 8.8 CVE-2024-8533 A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permi… 2800c Optixpanel Compact Firmware 4.0.2.106 / 4.0.2.116+ Fix from $1,9502024-09-12 HIGH 7.3 CVE-2024-7890 Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows Workspace 2203.1 / 2405+ Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-5760 The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the t… Universal Print Driver Mitigation only Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-8306 CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability… Vijeo Designer 6.3+ Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-40657 In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy. This … Android Patch available Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-40658 In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local esc… Android Patch available Fix from $1,9502024-09-11 HIGH 7.8 CVE-2024-40662 In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation … Android Patch available Fix from $1,9502024-09-11 CRITICAL 9.8 CVE-2024-44893 An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request. Jimureport No fix yet Fix from $2,3002024-09-10 HIGH 7.8 CVE-2024-38014 KEVEPSS 6% Windows Installer Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20766 / 10.0.14393.7336+ Fix from $1,9502024-09-10 CRITICAL 9.8 CVE-2024-37980 Microsoft SQL Server Elevation of Privilege Vulnerability Sql Server 2016 13.0.6445.1 / 13.0.7040.1+ Fix from $2,3002024-09-10 HIGH 8.8 CVE-2024-45041 External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called d… External Secrets Operator 0.10.2+ Fix from $1,9502024-09-09 CRITICAL 9.8 CVE-2024-7493 The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin … Wpcom Member 1.5.3+ Fix from $2,3002024-09-06 HIGH 8.8 CVE-2024-8247 The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin n… Newsletters 4.9.9.3+ Fix from $1,9502024-09-06 HIGH 8.8 CVE-2024-45173 An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vul… C Mor Video Surveillance No fix yet Fix from $1,9502024-09-05 HIGH 8.1 CVE-2024-45058 i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to… I Educar after 2.9 Fix from $1,9502024-08-28 HIGH 7.5 CVE-2024-4555 Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affec… Netiq Access Manager 5.0.4.1+ Fix from $1,9502024-08-28 HIGH 7.5 CVE-2024-42774 An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthentica… Hotel Management System No fix yet Fix from $1,9502024-08-22 CRITICAL 9.4 CVE-2024-36439 Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, wi… Mitigation only Fix from $2,3002024-08-22 HIGH 7.8 CVE-2024-33656 The DXE module SmmComputrace contains a vulnerability that allows local attackers to leak stack or global memory. This could lead to privilege escala… Aptio V after 5.36 Fix from $1,9502024-08-21 HIGH 7.5 CVE-2020-11846 A vulnerability found in OpenText Privileged Access Manager that issues a token. on successful issuance of the token, a cookie gets set that allows u… Netiq Privileged Access Manager 3.7+ Fix from $1,9502024-08-21 HIGH 7.8 CVE-2023-22576 Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged … Repository Manager 3.4.3+ Fix from $1,9502024-08-21 HIGH 8.8 CVE-2024-43403 Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, which is bound with a Cluster… Mitigation only Fix from $1,9502024-08-20 CRITICAL 9.8 CVE-2024-33872 Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privilege… Mitigation only Fix from $2,3002024-08-20 CRITICAL 9.8 CVE-2024-43311 Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affects Login As Users: from n/a t… Mitigation only Fix from $2,3002024-08-19 CRITICAL 9.8 CVE-2024-43245 Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch: from n/a through 2.3.4. Mitigation only Fix from $2,3002024-08-19 HIGH 8.0 CVE-2024-43401 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can … Xwiki after 15.9 Fix from $1,9502024-08-19 CRITICAL 9.8 CVE-2024-44076 In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access. Microcks 1.10.0+ Fix from $2,3002024-08-19