Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2024-40781 The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker… macOS 12.7.6 / 13.6.8+ Fix from $1,9502024-07-29 HIGH 7.8 CVE-2024-27826 The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.6, macOS Sonoma 14.5, mac… Ipados 1.3 / 10.5+ Fix from $1,9502024-07-29 CRITICAL 9.8 CVE-2024-37858 SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis… Lost And Found Information System Mitigation only Fix from $2,3002024-07-29 HIGH 7.0 CVE-2024-42050 The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user c… Streamer 3.7.0.0+ Fix from $1,9502024-07-28 MEDIUM 5.8 CVE-2024-27357 An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and WithSecu… Mitigation only Fix from $1,6002024-07-26 HIGH 7.8 CVE-2023-50700 Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be called by unprivileged users via … Mitigation only Fix from $1,9502024-07-26 MEDIUM 6.5 CVE-2024-41666 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD has a Web-based terminal that allows users to get a shell inside a … Argo Cd 2.9.21 / 2.10.16+ Fix from $1,6002024-07-24 HIGH 8.8 CVE-2020-11640 AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the command queue can use it to launch an attack by runn… Advabuild 3.7+ Fix from $1,9502024-07-23 MEDIUM 6.5 CVE-2024-1575 The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated … Nwa50ax Firmware 7.00+ Fix from $1,6002024-07-23 MEDIUM 6.5 CVE-2024-24970 Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which … No fix yet Fix from $1,6002024-07-19 MEDIUM 6.0 CVE-2024-6908 Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin via a crafted PUT HTTP reque… Patch available Fix from $1,6002024-07-19 MEDIUM 6.5 CVE-2024-30473 Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could potentiall… Elastic Cloud Storage 3.8.1.1+ Fix from $1,6002024-07-18 CRITICAL 9.3 CVE-2023-4976 A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows a… Mitigation only Fix from $2,3002024-07-17 HIGH 8.2 CVE-2024-21141 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.… Vm Virtualbox 7.0.20+ Fix from $1,9502024-07-16 MEDIUM 6.5 CVE-2024-5566 An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related… Enterprise Server 3.9.17 / 3.10.14+ Fix from $1,6002024-07-16 MEDIUM 5.5 CVE-2024-6326 An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this… Factorytalk Policy Manager Mitigation only Fix from $1,6002024-07-16 MEDIUM 6.5 CVE-2024-6325 The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-ad… Factorytalk Policy Manager Mitigation only Fix from $1,6002024-07-16 HIGH 8.0 CVE-2024-37560 Improper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege Escalation.This issue affects WP User Switch: from n/a throu… Mitigation only Fix from $1,9502024-07-12 HIGH 7.8 CVE-2024-6677 Privilege escalation in uberAgent Uberagent 7.2.1+ Fix from $1,9502024-07-12 CRITICAL 9.8 CVE-2024-6624 The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper con… Json Api User 3.9.4+ Fix from $2,3002024-07-11 HIGH 7.8 CVE-2024-6151 Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps a… Virtual Apps And Desktops after 2311 Fix from $1,9502024-07-10 HIGH 7.8 CVE-2024-6286 Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows Workspace 2203.1 / 2403.1+ Fix from $1,9502024-07-10 HIGH 7.2 CVE-2024-3325 Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0. Jasperreports Server after 8.0.4 Fix from $1,9502024-07-10 HIGH 8.8 CVE-2024-6411 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi… Profilegrid 5.9.0+ Fix from $1,9502024-07-10 HIGH 7.8 CVE-2024-31334 In DevmemIntFreeDefBackingPage of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead … Android Mitigation only Fix from $1,9502024-07-09 HIGH 7.0 CVE-2024-34725 In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalat… Android Mitigation only Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31318 In CompanionDeviceManagerService.java, there is a possible way to pair a companion device without user acceptance due to a missing permission check. … Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31320 In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM… Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31322 In updateServicesLocked of AccessibilityManagerService.java, there is a possible way for an app to be hidden from the Setting while retaining Accessi… Android Patch available Fix from $1,9502024-07-09 HIGH 7.8 CVE-2024-31323 In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local… Android Patch available Fix from $1,9502024-07-09