Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
MEDIUM 6.1 CVE-2024-21034 Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a… Complex Maintenance Repair And Overhaul after 12.2.13 Fix from $1,6002024-04-16 HIGH 8.8 CVE-2024-32003 wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes … Mitigation only Fix from $1,9502024-04-12 MEDIUM 5.0 CVE-2024-3388 A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to impersonate another user and … Pan Os 8.1.26 / 9.0.17+ Fix from $1,6002024-04-10 HIGH 7.8 CVE-2024-29052 Windows Storage Elevation of Privilege Vulnerability Windows 10 21h2 10.0.19044.4291 / 10.0.19045.4291+ Fix from $1,9502024-04-09 HIGH 7.8 CVE-2024-28904 Microsoft Brokering File System Elevation of Privilege Vulnerability Windows Server 2022 23h2 10.0.25398.830+ Fix from $1,9502024-04-09 HIGH 7.8 CVE-2024-28905 Microsoft Brokering File System Elevation of Privilege Vulnerability Windows Server 2022 23h2 10.0.25398.830+ Fix from $1,9502024-04-09 HIGH 7.2 CVE-2024-21324 Microsoft Defender for IoT Elevation of Privilege Vulnerability Defender For Iot 24.1.3+ Fix from $1,9502024-04-09 HIGH 8.2 CVE-2024-0082 NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file request… Chatrtx 0.2.1+ Fix from $1,9502024-04-08 MEDIUM 6.2 CVE-2023-52543 Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability. Emui No fix yet Fix from $1,6002024-04-08 HIGH 7.5 CVE-2023-52716 Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerabil… Emui Mitigation only Fix from $1,9502024-04-07 HIGH 7.8 CVE-2024-29741 In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privileg… Android Mitigation only Fix from $1,9502024-04-05 HIGH 8.8 CVE-2024-31498 Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windows can op… Mitigation only Fix from $1,9502024-04-04 MEDIUM 6.0 CVE-2024-20282 A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to roo… Nexus Dashboard 3.1+ Fix from $1,6002024-04-03 HIGH 7.8 CVE-2024-0172 Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper privilege management security vulnerability. An unauthenticated local att… Poweredge R660 Firmware 1.5.6+ Fix from $1,9502024-04-03 HIGH 7.1 CVE-2024-3137 Improper Privilege Management in uvdesk/community-skeleton No fix yet Fix from $1,9502024-04-02 CRITICAL 9.8 CVE-2024-29667 SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges a… Mitigation only Fix from $2,3002024-03-29 CRITICAL 9.8 CVE-2023-49232 An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to brute-force the password reset… Mitigation only Fix from $2,3002024-03-29 HIGH 8.8 CVE-2024-23537 Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to versi… Fineract 1.9.0+ Fix from $1,9502024-03-29 MEDIUM 6.7 CVE-2024-25961 Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker coul… Powerscale Onefs 9.5.0.8 / 9.7.0.2+ Fix from $1,6002024-03-28 MEDIUM 6.5 CVE-2024-28247 The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been … Pi Hole 5.18+ Fix from $1,6002024-03-27 HIGH 7.2 CVE-2023-40289EPSS 18% A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privile… X11ssm F Firmware Mitigation only Fix from $1,9502024-03-27 HIGH 8.5 CVE-2024-1973 By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform u… Mitigation only Fix from $1,9502024-03-25 HIGH 8.1 CVE-2024-24892 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler … Mitigation only Fix from $1,9502024-03-25 HIGH 8.8 CVE-2024-2228 This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined Quick… Identityiq 8.1+ Fix from $1,9502024-03-22 HIGH 7.8 CVE-2023-41099 In the Windows installer in Atos Eviden CardOS API before 5.5.5.2811, Local Privilege Escalation can occur.(from a regular user to SYSTEM). Eviden Cardos Api 5.5.5.2811+ Fix from $1,9502024-03-22 CRITICAL 9.8 CVE-2023-48902 An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, dele… Autoexpress No fix yet Fix from $2,3002024-03-21 MEDIUM 6.5 CVE-2024-1908 An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Enterprise Actions GitH… Enterprise Server 3.8.16 / 3.9.11+ Fix from $1,6002024-03-21 HIGH 7.8 CVE-2024-2390 As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could all… Mitigation only Fix from $1,9502024-03-18 HIGH 7.8 CVE-2024-28851 The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addresse… Snowflake Hive Metastore Connector 2024-02-09+ Fix from $1,9502024-03-15 HIGH 8.8 CVE-2023-50677 An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi compon… Dgnd4000 Firmware Mitigation only Fix from $1,9502024-03-14