Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.3 CVE-2024-27301 Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall install… Support App 2.5.1+ Fix from $1,9502024-03-14 CRITICAL 9.8 CVE-2024-28391 SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privilege… B2b Quick Order Form 1.3.0+ Fix from $2,3002024-03-14 MEDIUM 6.4 CVE-2023-50726 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. "Local sync" is an Argo CD feature that allows developers to temporarily ov… Argo Cd 2.8.12 / 2.9.7+ Fix from $1,6002024-03-13 MEDIUM 5.5 CVE-2024-2431 An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in configurations that allow a us… Globalprotect 5.1.12 / 6.0.4+ Fix from $1,6002024-03-13 HIGH 7.0 CVE-2024-2432 A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs wit… Globalprotect 5.1.12 / 6.0.8+ Fix from $1,9502024-03-13 MEDIUM 6.5 CVE-2024-20262 A vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated, local attacker to create or… Mitigation only Fix from $1,6002024-03-13 HIGH 8.8 CVE-2024-1505 The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to… Academy Lms 1.9.20+ Fix from $1,9502024-03-13 HIGH 8.8 CVE-2024-1138 The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with … Mitigation only Fix from $1,9502024-03-12 HIGH 7.8 CVE-2024-26169 KEV Windows Error Reporting Service Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20526 / 10.0.14393.6796+ Fix from $1,9502024-03-12 HIGH 7.5 CVE-2024-28197 Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the… Zitadel 2.44.3+ Fix from $1,9502024-03-11 CRITICAL 9.1 CVE-2024-27207 Exported broadcast receivers allowing malicious apps to bypass broadcast protection. Android No fix yet Fix from $2,3002024-03-11 HIGH 7.8 CVE-2024-27210 In policy_check of fvp.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege wit… Android Mitigation only Fix from $1,9502024-03-11 HIGH 7.8 CVE-2024-27222 In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_P… Android Mitigation only Fix from $1,9502024-03-11 HIGH 7.8 CVE-2024-27224 In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with… Android Mitigation only Fix from $1,9502024-03-11 HIGH 7.8 CVE-2024-27233 In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege… Android Mitigation only Fix from $1,9502024-03-11 HIGH 7.8 CVE-2024-22008 In config_gov_time_windows of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr… Android Mitigation only Fix from $1,9502024-03-11 MEDIUM 6.7 CVE-2024-25987 In pt_sysctl_command of pt.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privil… Android Mitigation only Fix from $1,6002024-03-11 MEDIUM 6.4 CVE-2024-25990 In pktproc_perftest_gen_rx_packet_sktbuf_mode of link_rx_pktproc.c, there is a possible out of bounds write due to a race condition. This could lead … Android Mitigation only Fix from $1,6002024-03-11 HIGH 7.8 CVE-2024-0046 In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This c… Android Patch available Fix from $1,9502024-03-11 HIGH 7.8 CVE-2024-0049 In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with n… Android Patch available Fix from $1,9502024-03-11 HIGH 7.8 CVE-2024-23276 A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may b… macOS 12.7.4 / 13.6.5+ Fix from $1,9502024-03-08 HIGH 8.8 CVE-2024-1442 A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user acc… Grafana 9.5.7 / 10.0.12+ Fix from $1,9502024-03-07 HIGH 8.1 CVE-2024-22752 Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched… Mitigation only Fix from $1,9502024-03-07 HIGH 8.0 CVE-2024-2005 In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML auth… Blue Planet Inventory after 22.12 Fix from $1,9502024-03-06 CRITICAL 9.8 CVE-2023-38944EPSS 16% An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control a… Re160v Firmware No fix yet Fix from $2,3002024-03-06 HIGH 7.6 CVE-2024-1764 Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using th… Devolutions Server 2023.3.16.0+ Fix from $1,9502024-03-05 HIGH 7.5 CVE-2024-25842 An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before ve… Account Manager 9.0.0+ Fix from $1,9502024-03-03 CRITICAL 9.8 CVE-2024-25847 SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and … Product Catalog \(csv\, Excel\) Import after 6.5.0 Fix from $2,3002024-03-03 HIGH 7.8 CVE-2024-0819 Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged us… Remote 15.51.5+ Fix from $1,9502024-02-27 HIGH 7.8 CVE-2024-0197 A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local … Sentinel Hasp Ldk 9.16+ Fix from $1,9502024-02-27