Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
CRITICAL 9.8 CVE-2022-41923 Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targe… Spring Security Core 3.3.2 / 4.0.5+ Fix from $2,3002022-11-23 HIGH 7.5 CVE-2022-0222 A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller wh… Modicon M340 Bmxp341000 Firmware 3.50+ Fix from $1,9502022-11-22 HIGH 7.2 CVE-2022-42459 Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress. Image Hover Effects Ultimate after 9.7.1 Fix from $1,9502022-11-18 HIGH 7.8 CVE-2022-43308 INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies. Sg 2404 Poe Firmware No fix yet Fix from $1,9502022-11-18 CRITICAL 9.8 CVE-2022-43138 Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API. Dolibarr Erp\/crm 14.0.1+ Fix from $2,3002022-11-17 HIGH 8.8 CVE-2022-45183 Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve… Powershell Universal 2.12.6 / 3.4.7+ Fix from $1,9502022-11-14 HIGH 7.8 CVE-2022-41339 In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation. Manageengine Mobile Device Manager Plus Mitigation only Fix from $1,9502022-11-12 CRITICAL 9.9 CVE-2022-39395 Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server and Vela Worker prior to versio… Server 0.16.0 / 0.17.0+ Fix from $2,3002022-11-10 HIGH 7.5 CVE-2021-34579 In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft W… Fl Mguard Dm Mitigation only Fix from $1,9502022-11-09 CRITICAL 9.8 CVE-2022-37015 Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a typ… Endpoint Detection And Response 4.7.0+ Fix from $2,3002022-11-08 HIGH 7.8 CVE-2022-44732 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) befor… Cyber Protect Home Office 39900+ Fix from $1,9502022-11-07 HIGH 7.8 CVE-2022-44733 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) befor… Cyber Protect Home Office 39900+ Fix from $1,9502022-11-07 HIGH 7.8 CVE-2022-42796 This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.7 and iPadOS 15.7, macOS Ventura 13. An app may be able to ga… Ipados 13.0 / 15.7+ Fix from $1,9502022-11-01 HIGH 7.8 CVE-2022-32907 This issue was addressed with improved checks. This issue is fixed in tvOS 16, iOS 16, watchOS 9. An app may be able to execute arbitrary code with k… Iphone Os 9.0 / 16.0+ Fix from $1,9502022-11-01 HIGH 7.8 CVE-2022-32794 A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big … Mac Os X 10.15.7 / 11.6.6+ Fix from $1,9502022-11-01 MEDIUM 5.5 CVE-2022-3369 An Improper Access Control vulnerability in the bdservicehost.exe component, as used in Bitdefender Engines for Windows, allows an attacker to delete… Engines 7.92659+ Fix from $1,6002022-11-01 MEDIUM 6.5 CVE-2022-3419 The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users … Automatic User Roles Switcher 1.1.2+ Fix from $1,6002022-10-31 HIGH 7.8 CVE-2022-41974 multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. … Fedora 0.9.2+ Fix from $1,9502022-10-29 HIGH 8.8 CVE-2022-39286 Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code exec… Debian Linux 4.11.2+ Fix from $1,9502022-10-26 HIGH 8.8 CVE-2022-43749 Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-1601 allows remote authenticated… Presto File Server 2.1.2-1601+ Fix from $1,9502022-10-26 HIGH 8.8 CVE-2022-28169 Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, u… Fabric Operating System 8.2.3c / 9.0.1e+ Fix from $1,9502022-10-25 MEDIUM 6.7 CVE-2022-34438 Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges… Emc Powerscale Onefs after 9.4.0.5 Fix from $1,6002022-10-21 HIGH 8.8 CVE-2022-41835 In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to … F5os A 1.1.0 / 1.5.0+ Fix from $1,9502022-10-19 HIGH 7.5 CVE-2022-39422 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.3… Vm Virtualbox 6.1.38+ Fix from $1,9502022-10-18 HIGH 8.8 CVE-2022-22239 An Execution with Unnecessary Privileges vulnerability in Management Daemon (mgd) of Juniper Networks Junos OS Evolved allows a locally authenticated… Junos Os Evolved 20.4+ Fix from $1,9502022-10-18 HIGH 7.3 CVE-2022-3421 An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-… Drive 64.0+ Fix from $1,9502022-10-17 MEDIUM 6.7 CVE-2022-2249 Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalat… Aura Communication Manager 8.1.3.4+ Fix from $1,6002022-10-12 HIGH 7.8 CVE-2022-41032 NuGet Client Elevation of Privilege Vulnerability Fedora 16.9.26 / 16.11.20+ Fix from $1,9502022-10-11 HIGH 7.5 CVE-2022-3422 Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the fo… Tooljet 1.26.1+ Fix from $1,9502022-10-07 MEDIUM 6.7 CVE-2022-2975 A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative us… Aura Application Enablement Services 8.1.3.5 / 10.1.0.2+ Fix from $1,6002022-10-06