Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2023-5993 A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege l… Safenet Authentication Client 10.8+ Fix from $1,9502024-02-27 HIGH 7.8 CVE-2023-7016 A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access. Safenet Authentication Client 10.8+ Fix from $1,9502024-02-27 CRITICAL 9.8 CVE-2024-24402 An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component. Nagios Xi Mitigation only Fix from $2,3002024-02-26 HIGH 8.8 CVE-2024-0439 As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most manager… Anythingllm 1.0.0+ Fix from $1,9502024-02-26 MEDIUM 6.7 CVE-2024-22235 VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can esca… Aria Operations 8.16.0+ Fix from $1,6002024-02-21 HIGH 7.8 CVE-2024-21892 On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated… Node.js 18.19.1 / 20.11.1+ Fix from $1,9502024-02-20 HIGH 7.8 CVE-2023-40106 In sanitizeSbn of NotificationManagerService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could le… Android Patch available Fix from $1,9502024-02-15 HIGH 7.8 CVE-2024-0622 Local privilege escalation vulnerability affects OpenText Operations Agent product versions 12.15 and 12.20-12.25 when installed on Non-Windows platf… Operations Agent after 12.25 Fix from $1,9502024-02-15 HIGH 7.2 CVE-2023-45581 An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site admi… Forticlient Enterprise Management Server 7.0.10+ Fix from $1,9502024-02-15 HIGH 7.8 CVE-2024-0353 Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permi… Endpoint Antivirus 7.3.10018.0 / 7.3.12013.0+ Fix from $1,9502024-02-15 MEDIUM 6.5 CVE-2023-25535 Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can … Supportassist For Home Pcs 3.13.2.19+ Fix from $1,6002024-02-14 HIGH 8.8 CVE-2023-52431 The Plack::Middleware::XSRFBlock package before 0.0.19 for Perl allows attackers to bypass a CSRF protection mechanism via an empty form value and an… \ 0.0.19+ Fix from $1,9502024-02-13 HIGH 8.8 CVE-2024-24830 OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability … Openobserve 0.8.0+ Fix from $1,9502024-02-08 MEDIUM 6.5 CVE-2024-25106 OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulne… Openobserve 0.8.0+ Fix from $1,6002024-02-08 CRITICAL 9.8 CVE-2023-47132 An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls. N Central 2023.7+ Fix from $2,3002024-02-08 HIGH 7.0 CVE-2024-22795 Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Complia… Secureconnector No fix yet Fix from $1,9502024-02-08 MEDIUM 6.7 CVE-2024-23764 Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and… Client Security No fix yet Fix from $1,6002024-02-08 HIGH 7.8 CVE-2024-22237 Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl… Aria Operations For Networks after 6.12.0 Fix from $1,9502024-02-06 HIGH 7.8 CVE-2024-22239 Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may expl… Aria Operations For Networks after 6.12.0 Fix from $1,9502024-02-06 HIGH 7.8 CVE-2023-32451 Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation a… Display Manager 2.1.1.21+ Fix from $1,9502024-02-06 HIGH 7.1 CVE-2023-28049 Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploi… Command \| Monitor 10.9.1+ Fix from $1,9502024-02-06 HIGH 7.8 CVE-2023-31005 IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 … Security Verify Access after 10.0.6.1 Fix from $1,9502024-02-03 HIGH 8.8 CVE-2023-36496 Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory… Pingdirectory after 9.1.0.2 Fix from $1,9502024-02-01 HIGH 8.8 CVE-2024-24747EPSS 34% MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` ac… Minio Patch available Fix from $1,9502024-01-31 HIGH 8.8 CVE-2024-21888EPSS 87% A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elev… Connect Secure Mitigation only Fix from $1,9502024-01-31 HIGH 7.8 CVE-2024-0832 In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In … Telerik Reporting 18.0.24.130+ Fix from $1,9502024-01-31 HIGH 7.8 CVE-2024-0833 In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer compon… Telerik Test Studio 2023.3.1330+ Fix from $1,9502024-01-31 HIGH 7.8 CVE-2024-0219 In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. … Telerik Justdecompile after 2019.1.118.0 Fix from $1,9502024-01-31 HIGH 7.8 CVE-2024-0674 Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissi… Douro Firmware Mitigation only Fix from $1,9502024-01-30 HIGH 7.6 CVE-2024-21985 ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authentica… Clustered Data Ontap 9.9.1 / 9.10.1+ Fix from $1,9502024-01-26