Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.3 CVE-2024-42995 VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module … Vtiger Crm after 8.1.0 Fix from $1,9502024-08-16 HIGH 7.8 CVE-2024-34741 In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be visible on the screensaver while… Android Patch available Fix from $1,9502024-08-15 HIGH 7.8 CVE-2024-34743 In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the code. This could lead to loca… Android Patch available Fix from $1,9502024-08-15 MEDIUM 6.7 CVE-2024-42440 Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS b… Meeting Software Development Kit 6.1.5+ Fix from $1,6002024-08-14 HIGH 8.8 CVE-2024-21807 Improper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an … Mitigation only Fix from $1,9502024-08-14 HIGH 7.2 CVE-2024-43121 Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: from n/a through 1.3.6.1. Husky Products Filter Professional For Woocommerce 1.3.6.2+ Fix from $1,9502024-08-13 HIGH 7.2 CVE-2024-41903 A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application mounts the contain… Sinec Traffic Analyzer 2.0+ Fix from $1,9502024-08-13 HIGH 8.8 CVE-2023-48171 An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component. Defectdojo 1.5.3.1+ Fix from $1,9502024-08-12 HIGH 7.8 CVE-2024-27442 An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the z… Collaboration 10.0.7+ Fix from $1,9502024-08-12 CRITICAL 9.0 CVE-2024-42366 VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-permission and cross-site script… Vrcx 2024.03.23+ Fix from $2,3002024-08-08 HIGH 8.8 CVE-2024-22069 There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal w… Zxv10 Et301 Firmware Mitigation only Fix from $1,9502024-08-08 HIGH 7.8 CVE-2024-43199 Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user. Ndoutils 2.1.4+ Fix from $1,9502024-08-07 CRITICAL 9.8 CVE-2024-6359 Privilege escalation vulnerability identified in OpenText ArcSight Intelligence. Arcsight Intelligence 6.4.13+ Fix from $2,3002024-08-06 HIGH 7.2 CVE-2024-7291 The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper … Mitigation only Fix from $1,9502024-08-03 HIGH 8.8 CVE-2024-33894 Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several proces… Ewon Cosy\+ Firmware 21.2s10 / 22.1s3+ Fix from $1,9502024-08-02 HIGH 8.8 CVE-2024-27181 In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Link… Linkis 1.6.0+ Fix from $1,9502024-08-02 MEDIUM 6.4 CVE-2024-41949 biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can… Biscuit Auth 5.0.0+ Fix from $1,6002024-08-01 HIGH 8.8 CVE-2024-39633 Improper Privilege Management vulnerability in IdeaBox PowerPack for Beaver Builder allows Privilege Escalation.This issue affects PowerPack for Beav… Mitigation only Fix from $1,9502024-08-01 HIGH 8.8 CVE-2024-39634 Improper Privilege Management vulnerability in IdeaBox PowerPack Pro for Elementor allows Privilege Escalation.This issue affects PowerPack Pro for E… Mitigation only Fix from $1,9502024-08-01 HIGH 7.2 CVE-2024-38775 Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Feed: from n/a through 6.5.6. Mitigation only Fix from $1,9502024-08-01 CRITICAL 9.8 CVE-2024-38770 Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This … Mitigation only Fix from $2,3002024-08-01 HIGH 8.0 CVE-2023-52209 Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Re… Mitigation only Fix from $1,9502024-08-01 HIGH 7.8 CVE-2024-40802 The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker… macOS 12.7.6 / 13.6.8+ Fix from $1,9502024-07-29 HIGH 7.8 CVE-2024-40781 The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker… macOS 12.7.6 / 13.6.8+ Fix from $1,9502024-07-29 HIGH 7.8 CVE-2024-27826 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.6, macOS Sonoma 14.5, mac… Ipados 1.3 / 10.5+ Fix from $1,9502024-07-29 CRITICAL 9.8 CVE-2024-37858 SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis… Lost And Found Information System Mitigation only Fix from $2,3002024-07-29 HIGH 7.0 CVE-2024-42050 The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user c… Streamer 3.7.0.0+ Fix from $1,9502024-07-28 MEDIUM 5.8 CVE-2024-27357 An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and WithSecu… Mitigation only Fix from $1,6002024-07-26 HIGH 7.8 CVE-2023-50700 Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be called by unprivileged users via … Mitigation only Fix from $1,9502024-07-26 MEDIUM 6.5 CVE-2024-41666 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows users to get a shell inside a … Argo Cd 2.9.21 / 2.10.16+ Fix from $1,6002024-07-24