Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2023-4239
The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restrict…
Real Estate Manager
after 6.7.1
HIGH 7.8
CVE-2023-39211
Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable a…
Rooms
5.15.5+
HIGH 7.2
CVE-2023-4009
In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admi…
Ops Manager Server
5.0.22 / 6.0.17+
HIGH 7.8
CVE-2023-39520
Cryptomator encrypts data being stored on cloud infrastructure. The MSI installer provided on the homepage for Cryptomator version 1.9.2 allows local…
Cryptomator
1.9.3+
HIGH 8.8
CVE-2023-4140
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient r…
Wp Ultimate Csv Importer
after 7.9.8
HIGH 7.8
CVE-2023-20216
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevat…
Broadworks Application Delivery Platform
23.0.2023.05 / 24.0.2023.05+
HIGH 7.8
CVE-2023-31432
Through manipulation of passwords or other variables, using commands such as portcfgupload, configupload, license, myid, a non-privileged user could …
Brocade Fabric Operating System
9.1.1c+
HIGH 7.8
CVE-2023-37907
Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI installer provided on the homep…
Cryptomator
1.9.2+
HIGH 8.8
CVE-2023-37917
KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can become admin by editing the `isadm…
Kubepi
1.6.5+
MEDIUM 6.5
CVE-2023-38187
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Edge Chromium
115.0.1901.183+
HIGH 8.0
CVE-2023-3467
Privilege Escalation to root administrator (nsroot)
Netscaler Application Delivery Controller
12.1-55.297 / 13.0-91.13+
HIGH 7.2
CVE-2023-30799
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attack…
Routeros
6.49.7+
HIGH 7.8
CVE-2023-22023
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Interface). The supported version that is affected is 11. E…
Solaris
Patch available
HIGH 7.8
CVE-2023-30988
The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor with command…
I
Patch available
HIGH 7.8
CVE-2023-30989
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access t…
I
Patch available
HIGH 7.8
CVE-2023-3513
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access…
Razer Central
after 7.11.0.558
HIGH 7.8
CVE-2023-3514
Improper Privilege Control in RazerCentralSerivce Named Pipe in Razer RazerCentral <=7.11.0.558 on Windows allows a malicious actor with local access…
Razer Central
after 7.11.0.558
HIGH 7.8
CVE-2023-24491
A vulnerability has been discovered in the Citrix Secure Access client for Windows
which, if exploited, could allow an attacker with access to an …
Secure Access Client
23.5.1.3+
CRITICAL 9.8
CVE-2023-30765
Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access controls that could allow an attacker to alter privilege …
Infrasuite Device Master
1.0.7+
HIGH 7.8
CVE-2023-27558
IBM Db2 on Windows 10.5, 11.1, and 11.5 may be vulnerable to a privilege escalation caused by at least one installed service using an unquoted servic…
Db2
Patch available
MEDIUM 6.5
CVE-2023-29256
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to an information disclosure due to improper pri…
Db2
Mitigation only
HIGH 7.8
CVE-2021-42082
Local users are able to execute scripts under root privileges.
POC
On the local host run the following command:
curl 'localhost:8154/qstor/qs_upgr…
Quantastor
6.0.0.355+
HIGH 7.5
CVE-2022-48515
Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect service confidentiality.
Emui
No fix yet
CRITICAL 9.8
CVE-2021-46894
Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation.
Emui
Mitigation only
MEDIUM 5.5
CVE-2023-30642
Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege functio…
Android
Mitigation only
HIGH 7.8
CVE-2023-25521
NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privileges by leveraging a weakness whe…
Dgx A100 Firmware
1.21+
MEDIUM 6.8
CVE-2023-21513
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in w…
Android
Mitigation only
HIGH 8.2
CVE-2021-31937
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Edge Chromium
91.0.864.37+
MEDIUM 6.5
CVE-2023-20136
A vulnerability in the OpenAPI of Cisco Secure Workload could allow an authenticated, remote attacker with the privileges of a read-only user to exec…
Secure Workload
3.7.1.40+
HIGH 7.8
CVE-2023-34146
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca…
Apex One
14.0.12518+