Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.0 CVE-2023-36721 Windows Error Reporting Service Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.4974 / 10.0.19041.3570+ Fix from $1,9502023-10-10 HIGH 8.4 CVE-2023-36569 Microsoft Office Elevation of Privilege Vulnerability 365 Apps Patch available Fix from $1,9502023-10-10 CRITICAL 9.8 CVE-2023-5214 In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified. Bolt 3.27.4+ Fix from $2,3002023-10-06 HIGH 7.8 CVE-2023-26236 An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is pos… Epp Firmware 8.00.22.0010+ Fix from $1,9502023-10-05 CRITICAL 9.8 CVE-2023-5402 A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the net… C Bus Toolkit after 1.16.3 Fix from $2,3002023-10-04 HIGH 8.8 CVE-2023-20235 A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Softwa… Ios Xe 17.3.1+ Fix from $1,9502023-10-04 HIGH 7.8 CVE-2023-44217 A local privilege escalation vulnerability in SonicWall Net Extender MSI client for Windows 10.2.336 and earlier versions allows a local low-privileg… Netextender after 10.2.336 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-36628 A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation. Purity\/\/fa after 6.4.5 Fix from $1,9502023-10-03 HIGH 7.8 CVE-2023-40375 Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command l… I Patch available Fix from $1,9502023-09-28 HIGH 8.8 CVE-2023-33972 Scylladb is a NoSQL data store using the seastar framework, compatible with Apache Cassandra. Authenticated users who are authorized to create tables… Scylladb after 5.2.8 Fix from $1,9502023-09-27 MEDIUM 5.3 CVE-2023-41312 Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatica… Emui No fix yet Fix from $1,6002023-09-27 HIGH 8.8 CVE-2023-41322 GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,… Glpi 10.0.10+ Fix from $1,9502023-09-27 HIGH 8.8 CVE-2023-41324 GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,… Glpi 10.0.10+ Fix from $1,9502023-09-27 HIGH 8.8 CVE-2023-41326EPSS 31% GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features,… Glpi 10.0.10+ Fix from $1,9502023-09-27 HIGH 7.5 CVE-2023-41309 Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability. Emui No fix yet Fix from $1,9502023-09-27 CRITICAL 9.8 CVE-2023-39375 SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges Siberiancms 4.20.44 / 5.0.4+ Fix from $2,3002023-09-27 MEDIUM 6.7 CVE-2023-34043 VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can esca… Aria Operations 4.4+ Fix from $1,6002023-09-27 CRITICAL 9.8 CVE-2023-43457 An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=us… Service Provider Management System No fix yet Fix from $2,3002023-09-25 HIGH 7.5 CVE-2023-41301 Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally. Emui No fix yet Fix from $1,9502023-09-25 HIGH 7.8 CVE-2023-43766 Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Security 15, WithSecu… Linux Protection Mitigation only Fix from $1,9502023-09-22 CRITICAL 9.8 CVE-2023-4662 Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue affects Saphira Connect: bef… Connect 9.0+ Fix from $2,3002023-09-15 CRITICAL 9.8 CVE-2023-36657 An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrator) can be abused for privile… Metadefender Kiosk after 4.6.1.9996 Fix from $2,3002023-09-15 MEDIUM 5.3 CVE-2023-42468 The com.cutestudio.colordialer application through 2.1.8-2 for Android allows a remote attacker to initiate phone calls without user consent, because… Color Phone after 2.1.8-2 Fix from $1,6002023-09-13 CRITICAL 9.8 CVE-2023-36765 Microsoft Office Elevation of Privilege Vulnerability Office Patch available Fix from $2,3002023-09-12 MEDIUM 5.5 CVE-2023-35671 In onHostEmulationData of HostEmulationManager.java, there is a possible way for a general purpose NFC reader to read the full card number and expiry… Android Patch available Fix from $1,6002023-09-11 HIGH 7.8 CVE-2023-35674 KEV In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local e… Android Patch available Fix from $1,9502023-09-11 HIGH 7.8 CVE-2023-35676 In createQuickShareAction of SaveImageInBackgroundTask.java, there is a possible way to trigger a background activity launch due to an unsafe Pending… Android Mitigation only Fix from $1,9502023-09-11 HIGH 7.8 CVE-2023-35667 In updateList of NotificationAccessSettings.java, there is a possible way to hide approved notification listeners in the settings due to a logic erro… Android Patch available Fix from $1,9502023-09-11 MEDIUM 6.7 CVE-2023-20193 A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary fi… Identity Services Engine after 3.3 Fix from $1,6002023-09-07 HIGH 8.8 CVE-2020-10129 SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to access Admin functionality. Searchblox 9.2.1+ Fix from $1,9502023-09-06