Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2023-34147
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca…
Apex One
14.0.12518+
HIGH 7.8
CVE-2023-34148
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to esca…
Apex One
14.0.12518+
HIGH 8.1
CVE-2023-34465
XWiki Platform is a generic wiki platform. Starting in version 11.8-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.2, `Mail.MailConfig` can be ed…
Xwiki
14.4.8 / 14.10.6+
HIGH 8.8
CVE-2023-31469
A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user wi…
Streampipes
after 0.91.0
HIGH 7.8
CVE-2023-25185
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN…
Asika Airscale Firmware
Mitigation only
HIGH 7.8
CVE-2023-25188
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from …
Asika Airscale Firmware
Mitigation only
HIGH 7.8
CVE-2023-2847
During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with the affected ESET product instal…
Cyber Security
7.3.3600.0 / 7.3.3700.0+
HIGH 7.8
CVE-2023-26062
A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute…
Web Element Manager
22r1+
HIGH 8.8
CVE-2023-2833EPSS 17%
The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on th…
Reviewx
after 1.6.13
HIGH 7.8
CVE-2023-3027
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value…
Advanced Cluster Management For Kubernetes
Mitigation only
CRITICAL 9.9
CVE-2023-32713
In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Str…
Splunk App For Stream
8.1.1+
CRITICAL 9.8
CVE-2023-33966
Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` …
Deno Runtime
Mitigation only
CRITICAL 9.8
CVE-2023-29734
An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database.
Edjing Mix
No fix yet
HIGH 8.8
CVE-2023-32696
CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the `ckan` user (equivalen…
Ckan
2.9.9+
MEDIUM 6.7
CVE-2022-45853
The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version
V2.70(AAHH.3) and the GS1900-8HP firmware version V2.70(AAHI.3) could…
Gs1900 8 Firmware
Mitigation only
HIGH 7.8
CVE-2023-30601
Privilege escalation when enabling FQL/Audit logs allows user with JMX access to run arbitrary commands as the user running Apache Cassandra
This iss…
Cassandra
4.0.10 / 4.1.2+
CRITICAL 9.8
CVE-2023-31062
Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.…
Inlong
after 1.6.0
HIGH 7.5
CVE-2023-1693
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.
Emui
3.1.0+
HIGH 7.5
CVE-2023-1694
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.
Emui
3.1.0+
HIGH 7.8
CVE-2022-45452
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acron…
Agent
15+
MEDIUM 5.5
CVE-2023-29819
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to bypass protections via a craft…
Secureanywhere
after 9.0.33.39
MEDIUM 5.4
CVE-2023-25834
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to acces…
Portal For Arcgis
after 10.9.1
HIGH 7.1
CVE-2020-23362
Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter.
Yershop
No fix yet
HIGH 7.5
CVE-2023-29350
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Edge Chromium
113.0.1774.35+
CRITICAL 9.9
CVE-2023-22651
Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook…
Rancher
after 2.7.2
HIGH 8.8
CVE-2022-3405EPSS 5%
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acron…
Cyber Backup
No fix yet
MEDIUM 5.9
CVE-2023-29056
A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be confi…
Thinkagile Hx5530 Firmware
2.93_afbt30p / 3.72_tei388s+
CRITICAL 9.8
CVE-2023-1966
Instruments with Illumina Universal Copy Service v1.x and
v2.x contain an unnecessary privileges vulnerability. An unauthenticated
malicious actor co…
Iscan Firmware
after 1.3.1
MEDIUM 6.6
CVE-2023-30024
The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access…
A921 Firmware
No fix yet
MEDIUM 5.7
CVE-2023-28261
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Edge Chromium
110.0.1587.78 / 111.0.1661.54+