Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.8 CVE-2022-46356 Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and informat… Security Manager 3.9+ Fix from $1,9502023-01-30 MEDIUM 6.3 CVE-2023-23629 Metabase is an open source data analytics platform. Affected versions are subject to Improper Privilege Management. As intended, recipients of dashbo… Metabase 0.43.7.1 / 0.44.6.1+ Fix from $1,6002023-01-28 MEDIUM 6.5 CVE-2023-23610 GLPI is a Free Asset and IT Management Software package. Versions prior to 9.5.12 and 10.0.6 are vulnerable to Improper Privilege Management. Any use… Glpi 9.5.12 / 10.0.6+ Fix from $1,6002023-01-26 HIGH 7.8 CVE-2022-43997 Incorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation. There is an insufficiently pr… Aternity 12.1.4.27+ Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-38775 An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privi… Endpoint Security 8.4.1+ Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-38774 An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users … Endgame 7.17.7 / 8.4.0+ Fix from $1,9502023-01-26 HIGH 8.8 CVE-2023-0101 A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. An authenticated attacker cou… Nessus 8.15.8 / 10.4.2+ Fix from $1,9502023-01-20 HIGH 7.8 CVE-2022-25631 Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnerability, which is a type of is… Symantec Endpoint Protection 14.3.9210.6000+ Fix from $1,9502023-01-20 HIGH 7.5 CVE-2023-22331 Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user c… Conprosys Hmi System after 3.4.5 Fix from $1,9502023-01-20 HIGH 8.8 CVE-2023-0242 Rapid7 Velociraptor allows users to be created with different privileges on the server. Administrators are generally allowed to run any command on th… Velociraptor 0.6.7-5+ Fix from $1,9502023-01-18 HIGH 7.8 CVE-2023-22809EPSS 55% In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VIS… Debian Linux 1.9.12 / 13.4+ Fix from $1,9502023-01-18 MEDIUM 5.3 CVE-2021-4314 It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT token as any user. This is happ… Zowe Api Mediation Layer 1.19.0+ Fix from $1,6002023-01-18 HIGH 8.8 CVE-2023-21848 Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Admin Configuration). The supporte… Communications Convergence Patch available Fix from $1,9502023-01-18 HIGH 8.8 CVE-2022-39182 H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may allow a malicious actor to gain … Tardis 2000 No fix yet Fix from $1,9502023-01-12 HIGH 7.8 CVE-2023-21772 Windows Kernel Elevation of Privilege Vulnerability Windows 10 1607 No fix yet Fix from $1,9502023-01-10 HIGH 7.8 CVE-2023-21773 Windows Kernel Elevation of Privilege Vulnerability Windows 10 1607 No fix yet Fix from $1,9502023-01-10 HIGH 7.8 CVE-2023-21774 Windows Kernel Elevation of Privilege Vulnerability Windows 10 1607 Mitigation only Fix from $1,9502023-01-10 HIGH 7.8 CVE-2023-21755 Windows Kernel Elevation of Privilege Vulnerability Windows 10 1607 No fix yet Fix from $1,9502023-01-10 HIGH 7.8 CVE-2023-21730 Microsoft Cryptographic Services Elevation of Privilege Vulnerability Windows 10 1607 No fix yet Fix from $1,9502023-01-10 HIGH 7.8 CVE-2023-21561 Microsoft Cryptographic Services Elevation of Privilege Vulnerability Windows 10 1607 Mitigation only Fix from $1,9502023-01-10 HIGH 7.0 CVE-2023-21542 Windows Installer Elevation of Privilege Vulnerability Windows 10 1607 Mitigation only Fix from $1,9502023-01-10 HIGH 8.8 CVE-2023-21549 Windows SMB Witness Service Elevation of Privilege Vulnerability Windows 10 1607 Mitigation only Fix from $1,9502023-01-10 HIGH 7.8 CVE-2023-21551 Microsoft Cryptographic Services Elevation of Privilege Vulnerability Windows 10 1809 No fix yet Fix from $1,9502023-01-10 HIGH 7.8 CVE-2023-21552 Windows GDI Elevation of Privilege Vulnerability Windows 10 1607 No fix yet Fix from $1,9502023-01-10 HIGH 7.0 CVE-2023-21531 Azure Service Fabric Container Elevation of Privilege Vulnerability Azure Service Fabric No fix yet Fix from $1,9502023-01-10 HIGH 7.8 CVE-2022-4294 Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an at… Avira Security 1.1.78 / 22.10+ Fix from $1,9502023-01-10 CRITICAL 9.8 CVE-2022-0668 JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a specially crafted request is… Artifactory 6.23.41 / 7.37.13+ Fix from $2,3002023-01-08 HIGH 7.8 CVE-2022-43534 A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful e… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502023-01-05 HIGH 7.8 CVE-2022-43535 A vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate their user privileges. A successf… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502023-01-05 HIGH 7.8 CVE-2022-43533 A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A successful e… Clearpass Policy Manager 6.9.12 / 6.10.7+ Fix from $1,9502023-01-05