Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2023-34147 An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca… Apex One 14.0.12518+ Fix from $1,9502023-06-26 HIGH 7.8 CVE-2023-34148 An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca… Apex One 14.0.12518+ Fix from $1,9502023-06-26 HIGH 8.1 CVE-2023-34465 XWiki Platform is a generic wiki platform. Starting in version 11.8-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.2, `Mail.MailConfig` can be ed… Xwiki 14.4.8 / 14.10.6+ Fix from $1,9502023-06-23 HIGH 8.8 CVE-2023-31469 A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user wi… Streampipes after 0.91.0 Fix from $1,9502023-06-23 HIGH 7.8 CVE-2023-25185 An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN… Asika Airscale Firmware Mitigation only Fix from $1,9502023-06-16 HIGH 7.8 CVE-2023-25188 An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from … Asika Airscale Firmware Mitigation only Fix from $1,9502023-06-16 HIGH 7.8 CVE-2023-2847 During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with the affected ESET product instal… Cyber Security 7.3.3600.0 / 7.3.3700.0+ Fix from $1,9502023-06-15 HIGH 7.8 CVE-2023-26062 A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute… Web Element Manager 22r1+ Fix from $1,9502023-06-14 HIGH 8.8 CVE-2023-2833EPSS 17% The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on th… Reviewx after 1.6.13 Fix from $1,9502023-06-06 HIGH 7.8 CVE-2023-3027 The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,9502023-06-05 CRITICAL 9.9 CVE-2023-32713 In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Str… Splunk App For Stream 8.1.1+ Fix from $2,3002023-06-01 CRITICAL 9.8 CVE-2023-33966 Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` … Deno Runtime Mitigation only Fix from $2,3002023-05-31 CRITICAL 9.8 CVE-2023-29734 An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database. Edjing Mix No fix yet Fix from $2,3002023-05-30 HIGH 8.8 CVE-2023-32696 CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the `ckan` user (equivalen… Ckan 2.9.9+ Fix from $1,9502023-05-30 MEDIUM 6.7 CVE-2022-45853 The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could… Gs1900 8 Firmware Mitigation only Fix from $1,6002023-05-30 HIGH 7.8 CVE-2023-30601 Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra This iss… Cassandra 4.0.10 / 4.1.2+ Fix from $1,9502023-05-30 CRITICAL 9.8 CVE-2023-31062 Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.… Inlong after 1.6.0 Fix from $2,3002023-05-22 HIGH 7.5 CVE-2023-1693 The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality. Emui 3.1.0+ Fix from $1,9502023-05-20 HIGH 7.5 CVE-2023-1694 The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality. Emui 3.1.0+ Fix from $1,9502023-05-20 HIGH 7.8 CVE-2022-45452 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acron… Agent 15+ Fix from $1,9502023-05-18 MEDIUM 5.5 CVE-2023-29819 An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a craft… Secureanywhere after 9.0.33.39 Fix from $1,6002023-05-12 MEDIUM 5.4 CVE-2023-25834 Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to acces… Portal For Arcgis after 10.9.1 Fix from $1,6002023-05-09 HIGH 7.1 CVE-2020-23362 Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter. Yershop No fix yet Fix from $1,9502023-05-09 HIGH 7.5 CVE-2023-29350 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Edge Chromium 113.0.1774.35+ Fix from $1,9502023-05-05 CRITICAL 9.9 CVE-2023-22651 Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook… Rancher after 2.7.2 Fix from $2,3002023-05-04 HIGH 8.8 CVE-2022-3405EPSS 5% Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acron… Cyber Backup No fix yet Fix from $1,9502023-05-03 MEDIUM 5.9 CVE-2023-29056 A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be confi… Thinkagile Hx5530 Firmware 2.93_afbt30p / 3.72_tei388s+ Fix from $1,6002023-04-28 CRITICAL 9.8 CVE-2023-1966 Instruments with Illumina Universal Copy Service v1.x and v2.x contain an unnecessary privileges vulnerability. An unauthenticated malicious actor co… Iscan Firmware after 1.3.1 Fix from $2,3002023-04-28 MEDIUM 6.6 CVE-2023-30024 The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access… A921 Firmware No fix yet Fix from $1,6002023-04-28 MEDIUM 5.7 CVE-2023-28261 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Edge Chromium 110.0.1587.78 / 111.0.1661.54+ Fix from $1,6002023-04-27