Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.7 CVE-2024-3507 Improper privilege management vulnerability in Lunar software that affects versions 6.0.2 through 6.6.0. This vulnerability allows an attacker to per… Mitigation only Fix from $1,9502024-05-08 HIGH 7.2 CVE-2024-22264 VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious actor with admin privileges on VMware Avi Load Balancer can creat… Mitigation only Fix from $1,9502024-05-08 HIGH 7.8 CVE-2024-23713 In migrateNotificationFilter of NotificationManagerService.java, there is a possible failure to persist notifications settings due to improper input … Android Patch available Fix from $1,9502024-05-07 HIGH 7.8 CVE-2024-0024 In multiple methods of UserManagerService.java, there is a possible failure to persist or enforce user restrictions due to improper input validation.… Android Patch available Fix from $1,9502024-05-07 HIGH 7.8 CVE-2024-23710 In assertPackageWithSharedUserIdIsPrivileged of InstallPackageHelper.java, there is a possible execution of arbitrary app code as a privileged app du… Android Patch available Fix from $1,9502024-05-07 HIGH 8.8 CVE-2024-29150 An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728.… Mitigation only Fix from $1,9502024-05-07 MEDIUM 6.7 CVE-2024-20021 In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege… Android Mitigation only Fix from $1,6002024-05-06 HIGH 7.5 CVE-2024-33398 There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate… Mitigation only Fix from $1,9502024-05-03 MEDIUM 6.5 CVE-2024-34146 Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing a… Git Server after 114.v068a_c7cc2574 Fix from $1,6002024-05-02 MEDIUM 6.2 CVE-2024-33393 An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token compo… Mitigation only Fix from $1,6002024-05-01 HIGH 7.8 CVE-2024-23457 The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. Thi… Client Connector 4.2.0.209+ Fix from $1,9502024-05-01 HIGH 7.9 CVE-2023-7241 Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious software to abuse WRSA.EXE to … Mitigation only Fix from $1,9502024-05-01 CRITICAL 9.8 CVE-2024-33775 An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet. Nagios Xi No fix yet Fix from $2,3002024-05-01 CRITICAL 9.1 CVE-2024-33308 An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate privileges via the Emergency Co… No fix yet Fix from $2,3002024-04-30 MEDIUM 6.7 CVE-2024-33522 In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below)… Patch available Fix from $1,6002024-04-29 HIGH 7.8 CVE-2024-27518 An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a crafted DL… Mitigation only Fix from $1,9502024-04-29 HIGH 8.1 CVE-2024-31502 An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /admin/core/… Mitigation only Fix from $1,9502024-04-26 CRITICAL 9.1 CVE-2024-25343 Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords. N300 Firmware Mitigation only Fix from $2,3002024-04-26 HIGH 7.8 CVE-2024-28241 The GLPI Agent is a generic management agent. Prior to version 1.7.2, a local user can modify GLPI-Agent code or used DLLs to modify agent logic and … Glpi Agent 1.7.2+ Fix from $1,9502024-04-25 CRITICAL 9.8 CVE-2023-51425 Improper Privilege Management vulnerability in Jacques Malgrange Rencontre – Dating Site allows Privilege Escalation.This issue affects Rencontre – D… Mitigation only Fix from $2,3002024-04-24 HIGH 8.7 CVE-2023-38292 Certain software builds for the TCL 20XE Android device contain a vulnerable, pre-installed app with a package name of com.tct.gcs.hiddenmenuproxy (v… Mitigation only Fix from $1,9502024-04-22 CRITICAL 9.8 CVE-2024-32418 An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component. Flusity No fix yet Fix from $2,3002024-04-22 HIGH 7.8 CVE-2024-4017 Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) allows DLL Side-Loading.This is… U Series Appliance 4.0.3+ Fix from $1,9502024-04-19 HIGH 7.8 CVE-2024-4018 Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escal… U Series Appliance 4.0.3+ Fix from $1,9502024-04-19 HIGH 7.2 CVE-2024-3470 An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy key pertaining to … Enterprise Server 3.11.8 / 3.12.2+ Fix from $1,9502024-04-19 HIGH 8.8 CVE-2024-21989 ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x are susceptible to a vulnerability which when successfully expl… Ontap Select Deploy Administration Utility after 9.14.1 Fix from $1,9502024-04-17 MEDIUM 5.3 CVE-2024-21118 Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affe… Outside In Technology Mitigation only Fix from $1,6002024-04-16 MEDIUM 6.5 CVE-2024-21121 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.… Vm Virtualbox 7.0.16+ Fix from $1,6002024-04-16 HIGH 7.8 CVE-2024-21111 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.… Vm Virtualbox 7.0.16+ Fix from $1,9502024-04-16 HIGH 7.8 CVE-2024-21059 Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Difficult to expl… Solaris Mitigation only Fix from $1,9502024-04-16