Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.5 CVE-2022-2498 An issue in pipeline subscriptions in GitLab EE affecting all versions from 12.8 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 trig… GitLab 15.0.5 / 15.1.4+ Fix from $1,9502022-08-05 CRITICAL 9.1 CVE-2022-35243 In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when running in Appliance mode, an… Big Ip Access Policy Manager 14.1.5 / 15.1.6.1+ Fix from $2,3002022-08-04 MEDIUM 6.7 CVE-2022-33962 In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, certai… Big Ip Access Policy Manager 14.1.5.1 / 15.1.6.1+ Fix from $1,6002022-08-04 CRITICAL 9.8 CVE-2022-2317 The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of … Simple Membership 4.1.3+ Fix from $2,3002022-08-01 HIGH 8.8 CVE-2022-2273 The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editing a profile, allowing member… Simple Membership 4.1.3+ Fix from $1,9502022-08-01 MEDIUM 6.5 CVE-2022-34338 IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provi… Robotic Process Automation 21.0.3+ Fix from $1,6002022-08-01 HIGH 8.1 CVE-2022-35291 Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin … Successfactors Mobile Mitigation only Fix from $1,9502022-07-27 MEDIUM 6.7 CVE-2022-20906 Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vul… Nexus Dashboard 2.2+ Fix from $1,6002022-07-22 MEDIUM 6.7 CVE-2022-20907 Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vul… Nexus Dashboard 2.2+ Fix from $1,6002022-07-22 HIGH 7.1 CVE-2022-26113 An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9,… Forticlient after 7.0.3 Fix from $1,9502022-07-19 HIGH 7.8 CVE-2022-30526 A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 through 5.30, USG FLEX 200 fir… Usg Flex 100w Firmware after 5.30 Fix from $1,9502022-07-19 MEDIUM 6.7 CVE-2022-26118 A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a loc… Fortianalyzer 6.4.8 / 7.0.4+ Fix from $1,6002022-07-18 MEDIUM 6.8 CVE-2022-34754 A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: A… Acti9 Powertag Link C \(a9xelc10 A\) Firmware after 2.12.0 Fix from $1,6002022-07-13 HIGH 7.8 CVE-2022-33708 Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities… Galaxy Store 4.5.41.8+ Fix from $1,9502022-07-12 HIGH 7.8 CVE-2022-33709 Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities… Galaxy Store 4.5.41.8+ Fix from $1,9502022-07-12 HIGH 7.8 CVE-2022-33710 Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activit… Galaxy Store 4.5.41.8+ Fix from $1,9502022-07-12 HIGH 8.2 CVE-2022-23720 PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT… Pingid Integration For Windows Login 2.8+ Fix from $1,9502022-06-30 HIGH 7.8 CVE-2017-20121 A vulnerability was found in Teradici Management Console 2.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functi… Pcoip Management Console No fix yet Fix from $1,9502022-06-30 CRITICAL 9.8 CVE-2017-20111 A vulnerability, which was classified as critical, was found in Teleopti WFM 7.1.0. This affects an unknown part of the component Administration. The… Teleopti Workforce Management No fix yet Fix from $2,3002022-06-29 HIGH 7.8 CVE-2017-20112 A vulnerability has been found in IVPN Client 2.6.6120.33863 and classified as critical. Affected by this vulnerability is an unknown functionality. … Ivpn No fix yet Fix from $1,9502022-06-29 HIGH 7.8 CVE-2017-20107 A vulnerability, which was classified as problematic, was found in ShadeYouVPN.com Client 2.0.1.11. Affected is an unknown function. The manipulation… Shadeyouvpn.com No fix yet Fix from $1,9502022-06-28 MEDIUM 5.3 CVE-2022-31039 Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though t… Greenlight 2.12.6+ Fix from $1,6002022-06-27 HIGH 8.8 CVE-2019-25071 A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or… Iphone Os 13.0+ Fix from $1,9502022-06-25 HIGH 7.5 CVE-2022-22390 IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege manag… Db2 Mitigation only Fix from $1,9502022-06-24 HIGH 7.8 CVE-2020-21046 A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2… Eagleget 2.1.6.40+ Fix from $1,9502022-06-24 CRITICAL 9.8 CVE-2022-2104 The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh and /bin/bash). Sepcos Control And Protection Relay Firmware 1.23.21 / 1.24.8+ Fix from $2,3002022-06-24 CRITICAL 9.8 CVE-2022-1517 LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can al… Local Run Manager after 3.1 Fix from $2,3002022-06-24 CRITICAL 9.8 CVE-2022-32535 The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combination with CVE-2022-23534 this c… Pra Es8p2s Firmware after 1.01.05 Fix from $2,3002022-06-23 HIGH 8.8 CVE-2022-32536 The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This woul… Pra Es8p2s Firmware after 1.01.05 Fix from $1,9502022-06-23 MEDIUM 5.3 CVE-2022-29526 Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function co… Go 1.17.10 / 1.18.2+ Fix from $1,6002022-06-23