Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
MEDIUM 5.5 CVE-2023-30713 Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change som… Android Mitigation only Fix from $1,6002023-09-06 HIGH 7.8 CVE-2023-32426 A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may be able to gain root privileges. macOS 13.3+ Fix from $1,9502023-09-06 HIGH 8.8 CVE-2023-29166 A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may be able to elevate privileges. Pro Video Formats 2.2.5+ Fix from $1,9502023-09-06 HIGH 7.8 CVE-2020-35593 BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host. Patrol Agent after 20.08.00 Fix from $1,9502023-09-05 HIGH 8.8 CVE-2023-40918 KnowStreaming 3.3.0 is vulnerable to Escalation of Privileges. Unauthorized users can create a new user with an admin role. Knowstreaming No fix yet Fix from $1,9502023-09-05 CRITICAL 9.8 CVE-2023-36100 An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/U… Icecms No fix yet Fix from $2,3002023-09-01 HIGH 8.8 CVE-2023-4697 Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2. Memos 0.13.2+ Fix from $1,9502023-09-01 HIGH 7.8 CVE-2023-41743 Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Off… Agent Mitigation only Fix from $1,9502023-08-31 CRITICAL 9.8 CVE-2023-31175 An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attac… Sel 5037 Sel Grid Configurator 4.5.0.20+ Fix from $2,3002023-08-31 HIGH 7.8 CVE-2022-45451 Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Off… Agent 40173+ Fix from $1,9502023-08-31 HIGH 8.8 CVE-2023-3636 The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restric… Wp Project Manager 2.6.5+ Fix from $1,9502023-08-31 HIGH 7.2 CVE-2023-20266 A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Managem… Emergency Responder Mitigation only Fix from $1,9502023-08-30 HIGH 8.8 CVE-2023-32457 Dell PowerScale OneFS, versions 8.2.2.x-9.5.0.x, contains an improper privilege management vulnerability. A remote attacker with low privileges could… Powerscale Onefs after 9.5.0.3 Fix from $1,9502023-08-29 CRITICAL 9.6 CVE-2019-13690 Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalat… Chrome 75.0.3770.80+ Fix from $2,3002023-08-25 HIGH 7.5 CVE-2023-32559 A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the de… Node.js after 20.5.0 Fix from $1,9502023-08-24 CRITICAL 9.8 CVE-2023-4404 The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insuffi… Charitable after 1.7.0.12 Fix from $2,3002023-08-23 CRITICAL 9.8 CVE-2023-38734 IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users… Robotic Process Automation after 21.0.7.1 Fix from $2,3002023-08-22 MEDIUM 5.5 CVE-2023-3699 An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage device… Data Master 4.2.3.rk91+ Fix from $1,6002023-08-22 HIGH 7.5 CVE-2021-35309 An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks. Syncthru Web Service No fix yet Fix from $1,9502023-08-22 HIGH 7.8 CVE-2023-32487 Dell PowerScale OneFS, 8.2.x - 9.5.0.x, contains an elevation of privilege vulnerability. A low privileged local attacker could potentially exploit t… Powerscale Onefs after 9.5.0.3 Fix from $1,9502023-08-16 MEDIUM 6.7 CVE-2023-32490 Dell PowerScale OneFS 8.2x -9.5x contains an improper privilege management vulnerability. A high privilege local attacker could potentially exploit t… Powerscale Onefs after 9.5.0.3 Fix from $1,6002023-08-16 HIGH 7.8 CVE-2023-21272 In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privil… Android Patch available Fix from $1,9502023-08-14 HIGH 7.8 CVE-2023-21269 In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. Thi… Android Patch available Fix from $1,9502023-08-14 HIGH 7.8 CVE-2023-38721 The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain … I Patch available Fix from $1,9502023-08-14 HIGH 8.0 CVE-2023-0872 The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elev… Horizon 32.0.2+ Fix from $1,9502023-08-14 HIGH 7.8 CVE-2023-3160 The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having pro… Endpoint Antivirus Mitigation only Fix from $1,9502023-08-14 MEDIUM 6.5 CVE-2023-4293 The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.… Premium Packages Sell Digital Products Securely after 5.7.5 Fix from $1,6002023-08-12 CRITICAL 9.8 CVE-2021-28411 An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote a… Ruoyi No fix yet Fix from $2,3002023-08-11 HIGH 7.8 CVE-2023-30680 Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege. Android Mitigation only Fix from $1,9502023-08-10 HIGH 7.2 CVE-2023-37859 In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker … Wp 6070 Wvps Firmware 4.0.10+ Fix from $1,9502023-08-09