Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2023-20565 Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access. Ryzen 3 5100 Firmware Mitigation only Fix from $1,9502023-11-14 HIGH 7.8 CVE-2022-41700 Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user t… Nuc Pro Software Suite 2.0.0.9+ Fix from $1,9502023-11-14 HIGH 8.0 CVE-2023-47629 DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as … Datahub 0.12.1+ Fix from $1,9502023-11-14 CRITICAL 9.8 CVE-2023-6099 A vulnerability classified as critical has been found in Shenzhen Youkate Industrial Facial Love Cloud Payment System up to 1.0.55.0.0.1. This affect… Facial Love Cloud Platform after 1.0.55.0.0.1 Fix from $2,3002023-11-13 HIGH 7.8 CVE-2023-47611 A CWE-269: Improper Privilege Management vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cint… Bgs5 Firmware Mitigation only Fix from $1,9502023-11-10 HIGH 7.1 CVE-2023-36024 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Edge Chromium 118.0.2088.102 / 119.0.2151.58+ Fix from $1,9502023-11-10 MEDIUM 5.3 CVE-2023-5549 Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not hav… Moodle 3.9.24 / 3.11.17+ Fix from $1,6002023-11-09 MEDIUM 6.7 CVE-2023-41138 The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process. Appsanywhere Client Mitigation only Fix from $1,6002023-11-09 HIGH 7.5 CVE-2023-46758 Permission management vulnerability in the multi-screen interaction module. Successful exploitation of this vulnerability may cause service exception… Harmonyos No fix yet Fix from $1,9502023-11-08 MEDIUM 5.3 CVE-2023-46756 Permission control vulnerability in the window management module. Successful exploitation of this vulnerability may cause malicious pop-up windows. Harmonyos Mitigation only Fix from $1,6002023-11-08 HIGH 7.5 CVE-2023-46771 Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality. Emui No fix yet Fix from $1,9502023-11-08 HIGH 7.5 CVE-2023-5978 In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updat… FreeBSD 13.2+ Fix from $1,9502023-11-08 MEDIUM 5.5 CVE-2023-35140 The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local use… Gs1900 48hpv2 Firmware after 2.70 Fix from $1,6002023-11-07 HIGH 7.8 CVE-2023-41036 Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC) mechanism which could lead … Macvim 178+ Fix from $1,9502023-11-07 HIGH 7.5 CVE-2023-43018 IBM CICS TX Standard 11.1 and Advanced 10.1, 11.1 performs an operation at a privilege level that is higher than the minimum level required, which cr… Cics Tx Patch available Fix from $1,9502023-11-03 HIGH 7.2 CVE-2023-5408 A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modif… Openshift Container Platform Patch available Fix from $1,9502023-11-02 CRITICAL 9.9 CVE-2023-20048EPSS 16% A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to ex… Secure Firewall Management Center after 7.3.1.1 Fix from $2,3002023-11-01 HIGH 7.3 CVE-2023-5847 Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Wind… Nessus 10.4.3 / 10.6.2+ Fix from $1,9502023-11-01 HIGH 7.8 CVE-2023-5739 Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege. Image Assistant 2.4.0.0 / 5.1.8+ Fix from $1,9502023-10-31 HIGH 7.8 CVE-2023-47101 The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalation during installation or rep… Openvpn Client 2.0.40+ Fix from $1,9502023-10-30 HIGH 7.8 CVE-2023-21374 In System UI, there is a possible factory reset protection bypass due to a logic error in the code. This could lead to local escalation of privilege … Android Mitigation only Fix from $1,9502023-10-30 MEDIUM 5.5 CVE-2023-21376 In Telephony, there is a possible way to retrieve the ICCID due to a logic error in the code. This could lead to local information disclosure with no… Android 14.0+ Fix from $1,6002023-10-30 HIGH 7.8 CVE-2023-21396 In Activity Manager, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privileg… Android 14.0+ Fix from $1,9502023-10-30 HIGH 7.8 CVE-2023-21397 In Setup Wizard, there is a possible way to save a WiFi network due to an insecure default value. This could lead to local escalation of privilege wi… Android 14.0+ Fix from $1,9502023-10-30 HIGH 7.8 CVE-2023-21343 In ActivityStarter, there is a possible background activity launch due to an unsafe PendingIntent. This could lead to local escalation of privilege w… Android 14.0+ Fix from $1,9502023-10-30 HIGH 7.8 CVE-2023-40685 Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with com… I Patch available Fix from $1,9502023-10-29 HIGH 7.8 CVE-2023-40686 Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with com… I Patch available Fix from $1,9502023-10-29 HIGH 7.8 CVE-2022-3701 A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local att… System Update Plugin 1.3.1.2 / 2.0.0.213+ Fix from $1,9502023-10-27 HIGH 7.8 CVE-2023-44219 A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local lo… Directory Services Connector 4.1.22+ Fix from $1,9502023-10-27 HIGH 7.8 CVE-2023-34057 VMware Tools contains a local privilege escalation vulnerability. A malicious actor with local user access to a guest virtual machine may elevate pri… Tools 12.1.1+ Fix from $1,9502023-10-27