Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.2 CVE-2022-26251 The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges. Synaman after 5.1 Fix from $1,9502022-04-06 HIGH 8.8 CVE-2021-39772 In Bluetooth, there is a possible way to access the a2dp audio control switch due to a missing permission check. This could lead to local escalation … Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39782 In Telephony, there is a possible unauthorized modification of the PLMN SIM file due to a missing permission check. This could lead to local escalati… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39783 In rcsservice, there is a possible way to modify TTY mode due to a missing permission check. This could lead to local escalation of privilege with no… Android Mitigation only Fix from $1,9502022-03-30 HIGH 7.8 CVE-2021-39784 In CellBroadcastReceiver, there is a possible path to enable specific cellular features due to a missing permission check. This could lead to local e… Android Mitigation only Fix from $1,9502022-03-30 CRITICAL 9.8 CVE-2003-5001 A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Dete… Iss Blackice Pc Protection Mitigation only Fix from $2,3002022-03-28 CRITICAL 10.0 CVE-2022-24783 Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where… Deno 1.20.3+ Fix from $2,3002022-03-25 CRITICAL 9.8 CVE-2022-24637EPSS 99% Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin… Open Web Analytics 1.7.4+ Fix from $2,3002022-03-18 MEDIUM 6.1 CVE-2022-24072 The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into the extension store web page vi… Whale 3.12.129.18+ Fix from $1,6002022-03-17 HIGH 7.8 CVE-2022-22141 'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL configurat… Centum Cs 3000 Firmware Mitigation only Fix from $1,9502022-03-11 HIGH 7.8 CVE-2022-24750 UltraVNC is a free and open source remote pc access software. A vulnerability has been found in versions prior to 1.3.8.0 in which the DSM plugin mod… Ultravnc 1.3.8.1+ Fix from $1,9502022-03-10 HIGH 7.8 CVE-2022-24931 Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to execute arbi… Android Mitigation only Fix from $1,9502022-03-10 MEDIUM 5.5 CVE-2022-20051 In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service… Android Mitigation only Fix from $1,6002022-03-10 HIGH 7.8 CVE-2022-23296 Windows Installer Elevation of Privilege Vulnerability Windows 10 Mitigation only Fix from $1,9502022-03-09 HIGH 7.8 CVE-2022-24408 A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1). The sc SUID binary on affec… Sinumerik Mc Firmware 1.15 / 6.15+ Fix from $1,9502022-03-08 HIGH 7.3 CVE-2022-25311 A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions)… Sinec Network Management System 1.0.3+ Fix from $1,9502022-03-08 CRITICAL 9.8 CVE-2022-0441EPSS 85% The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated use… Masterstudy Lms 2.7.6+ Fix from $2,3002022-03-07 CRITICAL 9.8 CVE-2022-25089EPSS 18% Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.Persiste… Printix after 1.3.1106.0 Fix from $2,3002022-03-03 HIGH 7.8 CVE-2022-23921 Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is on… Proficy Cimplicitiy after 11.1 Fix from $1,9502022-02-25 HIGH 7.8 CVE-2022-25636 net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. Thi… Linux Kernel 5.4.182 / 5.10.103+ Fix from $1,9502022-02-24 HIGH 7.8 CVE-2022-25372 Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go. Pritunl Client Electron 1.2.3019.52a+ Fix from $1,9502022-02-20 HIGH 7.2 CVE-2022-23604 x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool for Discord server moderatio… X26 Cogs 1.10.0+ Fix from $1,9502022-02-15 HIGH 7.8 CVE-2022-25150 In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges. Binisoft Windows Firewall Control 6.8.1.0+ Fix from $1,9502022-02-14 CRITICAL 9.8 CVE-2022-24927 Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permis… Video Player 7.3.15.30+ Fix from $2,3002022-02-11 CRITICAL 9.8 CVE-2021-22801 A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configured with sp… Connexium Network Manager Mitigation only Fix from $2,3002022-02-11 CRITICAL 9.9 CVE-2021-36302 All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user with stan… Emc Integrated System For Microsoft Azure Stack Hub Firmware after 2204 Fix from $2,3002022-02-09 MEDIUM 6.5 CVE-2021-3813 Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2. Chatwoot after 2.1.1 Fix from $1,6002022-02-09 HIGH 7.8 CVE-2021-37852 ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in … Endpoint Antivirus 7.3.2055.0 / 7.3.10014.0+ Fix from $1,9502022-02-09 HIGH 8.8 CVE-2022-22509 In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the… Fl Switch 2005 Firmware Mitigation only Fix from $1,9502022-02-02 MEDIUM 5.4 CVE-2021-45729 The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to cr… Wp Google Map 1.8.1+ Fix from $1,6002022-01-25