Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.8 CVE-2021-26594 In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: Thi… Directus after 8.8.1 Fix from $1,9502021-02-23 HIGH 7.8 CVE-2021-25630 "loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" che… Online 4.2.13 / 6.4.3+ Fix from $1,9502021-02-23 MEDIUM 5.3 CVE-2021-26697 The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allowed unauthenticated users to h… Airflow Mitigation only Fix from $1,6002021-02-17 HIGH 8.8 CVE-2021-23885 Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain elevated privileges through the Us… Web Gateway 8.2.17 / 9.2.8+ Fix from $1,9502021-02-17 HIGH 7.8 CVE-2021-20075 Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd. M\!dge Firmware No fix yet Fix from $1,9502021-02-16 MEDIUM 6.5 CVE-2020-35557 An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in us… Mbconnect24 after 2.11.2 Fix from $1,6002021-02-16 HIGH 8.1 CVE-2020-29031 An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the passwor… Gatemanager 8250 Firmware 9.0i / 9.2c+ Fix from $1,9502021-02-15 HIGH 7.8 CVE-2021-26936 The replay-sorcery program in ReplaySorcery 0.4.0 through 0.5.0, when using the default setuid-root configuration, allows a local attacker to escalat… Replaysorcery after 0.5.0 Fix from $1,9502021-02-10 HIGH 7.8 CVE-2021-0327 In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities. This could lea… Android Patch available Fix from $1,9502021-02-10 HIGH 7.8 CVE-2021-23876 Bypass Remote Procedure call in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbitrary … Total Protection 16.0.30+ Fix from $1,9502021-02-10 HIGH 7.8 CVE-2021-23874 KEV Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execu… Total Protection 16.0.30+ Fix from $1,9502021-02-10 HIGH 7.8 CVE-2020-26191 Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain a privilege escalation vulnerability. A user with ISI_PRIV_JOB_ENGINE may use the Permission… Emc Powerscale Onefs Mitigation only Fix from $1,9502021-02-09 HIGH 8.2 CVE-2020-35517 A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is abl… Qemu after 5.2.50 Fix from $1,9502021-01-28 HIGH 7.8 CVE-2020-6024 Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vu… Smartconsole Mitigation only Fix from $1,9502021-01-20 HIGH 7.8 CVE-2021-0223 A local privilege escalation vulnerability in telnetd.real of Juniper Networks Junos OS may allow a locally authenticated shell user to escalate priv… Junos Mitigation only Fix from $1,9502021-01-15 HIGH 7.8 CVE-2021-0204 A sensitive information disclosure vulnerability in delta-export configuration utility (dexp) of Juniper Networks Junos OS may allow a locally authen… Junos Mitigation only Fix from $1,9502021-01-15 CRITICAL 9.8 CVE-2021-20618 Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remote attackers to bypass authent… Acmailer after 4.0.2 Fix from $2,3002021-01-14 MEDIUM 5.5 CVE-2021-1258 A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges … Anyconnect Secure Mobility Client 4.9.03047 / 4.9.03049+ Fix from $1,6002021-01-13 CRITICAL 9.1 CVE-2020-9141 There is a improper privilege management vulnerability in some Huawei smartphone. Successful exploitation of this vulnerability can cause information… Emui No fix yet Fix from $2,3002021-01-13 HIGH 7.3 CVE-2021-1704 Windows Hyper-V Elevation of Privilege Vulnerability Windows 10 No fix yet Fix from $1,9502021-01-12 HIGH 7.3 CVE-2021-1706 Windows LUAFV Elevation of Privilege Vulnerability Windows 10 Mitigation only Fix from $1,9502021-01-12 HIGH 7.0 CVE-2021-1709 Windows Win32k Elevation of Privilege Vulnerability Windows 10 Mitigation only Fix from $1,9502021-01-12 HIGH 8.0 CVE-2021-1712 Microsoft SharePoint Elevation of Privilege Vulnerability Sharepoint Enterprise Server No fix yet Fix from $1,9502021-01-12 HIGH 8.0 CVE-2021-1719 Microsoft SharePoint Elevation of Privilege Vulnerability Sharepoint Enterprise Server No fix yet Fix from $1,9502021-01-12 HIGH 7.8 CVE-2021-1687 Windows WalletService Elevation of Privilege Vulnerability Windows 10 No fix yet Fix from $1,9502021-01-12 HIGH 7.8 CVE-2021-1688 Windows CSC Service Elevation of Privilege Vulnerability Windows 10 Mitigation only Fix from $1,9502021-01-12 HIGH 7.8 CVE-2021-1689 Windows Multipoint Management Elevation of Privilege Vulnerability Windows 10 Mitigation only Fix from $1,9502021-01-12 HIGH 7.8 CVE-2021-1690 Windows WalletService Elevation of Privilege Vulnerability Windows 10 No fix yet Fix from $1,9502021-01-12 HIGH 7.8 CVE-2021-1693 Windows CSC Service Elevation of Privilege Vulnerability Windows 10 No fix yet Fix from $1,9502021-01-12 HIGH 7.5 CVE-2021-1694 Windows Update Stack Elevation of Privilege Vulnerability Windows 10 Mitigation only Fix from $1,9502021-01-12