Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2024-23620 An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated attacker can exploit this vul… Merge Efilm Workstation after 4.2 Fix from $1,9502024-01-26 CRITICAL 9.8 CVE-2024-22922 An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page… Visitor Management System Mitigation only Fix from $2,3002024-01-25 HIGH 8.8 CVE-2023-43317 An issue in Coign CRM Portal v.06.06 allows a remote attacker to escalate privileges via the userPermissionsList parameter in Session Storage compone… Coign No fix yet Fix from $1,9502024-01-24 HIGH 7.8 CVE-2023-52093 An exposed dangerous function vulnerability in the Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected install… Apex One 14.0.12849+ Fix from $1,9502024-01-23 HIGH 7.8 CVE-2023-52337 An improper access control vulnerability in Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could all… Deep Security Mitigation only Fix from $1,9502024-01-23 HIGH 7.8 CVE-2023-47201 A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on a… Apex One 14.0.12737+ Fix from $1,9502024-01-23 HIGH 8.8 CVE-2024-0751 A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunde… Firefox 115.7 / 122.0+ Fix from $1,9502024-01-23 HIGH 7.5 CVE-2023-52105 The nearby module has a privilege escalation vulnerability. Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,9502024-01-16 HIGH 7.5 CVE-2023-52116 Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exception… Emui Mitigation only Fix from $1,9502024-01-16 HIGH 7.5 CVE-2023-52107 Vulnerability of permissions being not strictly verified in the WMS module. Successful exploitation of this vulnerability may affect service confiden… Emui Mitigation only Fix from $1,9502024-01-16 HIGH 7.5 CVE-2023-52114 Data confidentiality vulnerability in the ScreenReader module. Successful exploitation of this vulnerability may affect service integrity. Emui No fix yet Fix from $1,9502024-01-16 HIGH 7.8 CVE-2023-6735 Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges Checkmk after 2.0.0 Fix from $1,9502024-01-12 HIGH 7.8 CVE-2023-6740 Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges Checkmk after 2.0.0 Fix from $1,9502024-01-12 CRITICAL 9.8 CVE-2024-21638 Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP … Azure Ipam 3.0.0+ Fix from $2,3002024-01-10 MEDIUM 5.5 CVE-2022-32931 This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app with root privileges may be able to access pr… macOS 13.0+ Fix from $1,6002024-01-10 HIGH 8.8 CVE-2023-44250 An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy H… Fortiproxy Mitigation only Fix from $1,9502024-01-10 HIGH 7.8 CVE-2023-47145 IBM Db2 for Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow a local user to escalate their privileges to the SYSTEM user using… Db2 10.5.0.11 / 11.1.4.7+ Fix from $1,9502024-01-07 MEDIUM 5.5 CVE-2023-41784 Permissions and Access Control Vulnerability in ZTE Red Magic 8 Pro Redmagic 8 Pro Firmware No fix yet Fix from $1,6002024-01-04 HIGH 8.8 CVE-2024-21622 Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x… Craft Cms 3.9.6+ Fix from $1,9502024-01-03 MEDIUM 6.5 CVE-2023-30617 Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1, 1.4.1, and 1.5… Kruise 1.3.1 / 1.4.1+ Fix from $1,6002024-01-03 CRITICAL 9.8 CVE-2023-50921 An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. T… Gl Mt1300 Firmware Mitigation only Fix from $2,3002024-01-03 HIGH 7.8 CVE-2023-41776 There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to es… Zxcloud Irai 7.23.32+ Fix from $1,9502024-01-03 HIGH 7.8 CVE-2023-48418 In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default… Pixel Watch Firmware No fix yet Fix from $1,9502024-01-02 CRITICAL 9.8 CVE-2023-48419 An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege  Nest Audio Firmware 2.58+ Fix from $2,3002024-01-02 HIGH 8.0 CVE-2023-7080 The V8 inspector intentionally allows arbitrary code execution within the Workers sandbox for debugging. wrangler dev would previously start an inspe… Wrangler 2.20.2 / 3.19.0+ Fix from $1,9502023-12-29 MEDIUM 5.5 CVE-2023-51433 Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. Magic Ui 6.1.0.212+ Fix from $1,6002023-12-29 HIGH 7.1 CVE-2023-51435 Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. Magic Ui 6.1.0.212+ Fix from $1,9502023-12-29 MEDIUM 5.5 CVE-2023-51429 Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. Magic Os 7.0.0.156+ Fix from $1,6002023-12-29 MEDIUM 5.5 CVE-2023-51430 Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. Magic Ui 6.1.0.212+ Fix from $1,6002023-12-29 MEDIUM 5.5 CVE-2023-23438 Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions Lge An00 Firmware 6.0.0.188+ Fix from $1,6002023-12-29