Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2021-1839
The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Updat…
Mac Os X
11.3+
HIGH 7.8
CVE-2021-1813
A validation issue was addressed with improved logic. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS …
Ipados
7.4 / 11.3+
CRITICAL 9.8
CVE-2021-35946
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore elevate thei…
Owncloud
10.8.0+
HIGH 7.2
CVE-2021-39192
Ghost is a Node.js content management system. An error in the implementation of the limits service between versions 4.0.0 and 4.9.4 allows all authen…
Ghost
4.10.0+
MEDIUM 5.3
CVE-2021-36930
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Edge
93.0.961.38+
HIGH 8.6
CVE-2021-30355EPSS 7%
Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privileges to root.
Kindle Firmware
after 5.13.4
HIGH 8.8
CVE-2021-37911
The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attackers can access any system dire…
Eh600 Firmware
after 01.00.30.00
CRITICAL 9.8
CVE-2021-39168
OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executo…
Contracts
3.4.2 / 4.3.1+
CRITICAL 9.8
CVE-2021-39167
OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executo…
Contracts
3.4.2 / 4.3.1+
HIGH 8.8
CVE-2021-1579
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…
Application Policy Infrastructure Controller
3.2 / 4.2+
HIGH 7.5
CVE-2021-29802
IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifie…
Resilient Security Orchestration Automation And Response
1.6.1+
HIGH 8.8
CVE-2021-24602
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via thei…
Hm Multiple Roles
1.3+
HIGH 7.8
CVE-2021-24038
Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle to an unprivileged process, l…
Desktop
31.1.0.67.507+
HIGH 7.8
CVE-2021-34745
A vulnerability in the AppDynamics .NET Agent for Windows could allow an attacker to leverage an authenticated, local user account to gain SYSTEM pri…
Appdynamics .net Agent
21.7+
HIGH 7.8
CVE-2021-37345
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scrip…
Nagios Xi
5.8.5+
HIGH 7.3
CVE-2021-36945
Windows 10 Update Assistant Elevation of Privilege Vulnerability
Windows 10 Update Assistant
Patch available
HIGH 7.8
CVE-2021-34483
Windows Print Spooler Elevation of Privilege Vulnerability
Windows 10
Patch available
HIGH 7.0
CVE-2021-34487
Windows Event Tracing Elevation of Privilege Vulnerability
Windows 10
Patch available
HIGH 7.8
CVE-2021-34537
Windows Bluetooth Driver Elevation of Privilege Vulnerability
Windows 10
Patch available
HIGH 7.8
CVE-2021-36927
Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability
Windows 7
Patch available
HIGH 7.8
CVE-2021-34471
Microsoft Defender Elevation of Privilege Vulnerability
Malware Protection Engine
1.1.18400.4+
HIGH 8.8
CVE-2020-24576
Netskope Client through 77 allows low-privileged users to elevate their privileges to NT AUTHORITY\SYSTEM.
Netskope
after 77
HIGH 7.2
CVE-2021-37627
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged r…
Contao
4.4.56 / 4.9.18+
HIGH 7.8
CVE-2021-21567
Dell PowerScale OneFS 9.1.0.x contains an improper privilege management vulnerability. It may allow an authenticated user with ISI_PRIV_LOGIN_SSH and…
Powerscale Onefs
Patch available
CRITICAL 9.8
CVE-2021-38140
The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AUTHORIZATION after set_user().
Set User
2.0.1+
HIGH 7.8
CVE-2021-1572
A vulnerability in ConfD could allow an authenticated, local attacker to execute arbitrary commands at the level of the account under which ConfD is …
Confd
after 7.5.2
HIGH 7.8
CVE-2021-22421
A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to cause further Eleva…
Harmonyos
Mitigation only
HIGH 8.8
CVE-2019-14453
An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus and logged fields, related to j…
Away From Home
No fix yet
HIGH 7.8
CVE-2021-22396
There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege m…
Ecns280 Td Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-37167
An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software befor…
Hmi 3 Control Panel Firmware
7.2.5.7+