Vulnerability index

Browse CVEs

3,012 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2020-7544 A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege e… Operator Terminal Expert Runtime 3.1+ Fix from $1,9502020-11-19 HIGH 8.8 CVE-2020-12495 Endress+Hauser Ecograph T (Neutral/Private Label) (RSG35, ORSG35) with Firmware version prior to V2.0.0 is prone to improper privilege management. Th… Rsg35 Firmware 2.0.0+ Fix from $1,9502020-11-19 MEDIUM 6.5 CVE-2020-3482 A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote … Expressway Mitigation only Fix from $1,6002020-11-18 HIGH 8.7 CVE-2020-26072 A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify informat… Iot Field Network Director 4.6.1+ Fix from $1,9502020-11-18 HIGH 8.8 CVE-2020-8269 An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285… Virtual Apps And Desktops 7.6 / 7.15+ Fix from $1,9502020-11-16 CRITICAL 9.8 CVE-2020-13638EPSS 77% lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been f… Rconfig 3.9.7+ Fix from $2,3002020-11-13 HIGH 7.5 CVE-2020-2022 An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administ… Pan Os 8.1.17 / 9.0.11+ Fix from $1,9502020-11-12 MEDIUM 5.4 CVE-2020-16993 Azure Sphere Elevation of Privilege Vulnerability Azure Sphere 20.08+ Fix from $1,6002020-11-11 HIGH 7.8 CVE-2020-16122 PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of… Ubuntu Linux Mitigation only Fix from $1,9502020-11-07 HIGH 7.8 CVE-2020-3593 A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating syste… Sd Wan 20.1.2 / 20.3.1+ Fix from $1,9502020-11-06 HIGH 7.8 CVE-2020-3594 A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating syste… Sd Wan 20.1.2 / 20.3.2+ Fix from $1,9502020-11-06 HIGH 7.8 CVE-2020-3595 A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root group on the underlying operating… Sd Wan 20.1.2 / 20.3.2+ Fix from $1,9502020-11-06 HIGH 7.8 CVE-2020-3600 A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating syste… Sd Wan 20.1.2 / 20.3.2+ Fix from $1,9502020-11-06 MEDIUM 6.7 CVE-2020-27122 A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to… Identity Services Engine 3.0.0+ Fix from $1,6002020-11-06 HIGH 7.8 CVE-2020-28046 An issue was discovered in ProlinOS through 2.4.161.8859R. An attacker with local code execution privileges as a normal user (MAINAPP) can escalate t… Prolinos after 2.4.161.8859r Fix from $1,9502020-11-02 CRITICAL 9.8 CVE-2020-27654 Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands… Router Manager 1.2.4-8081+ Fix from $2,3002020-10-29 CRITICAL 10.0 CVE-2020-27655 Improper access control vulnerability in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to access restricted resources via i… Router Manager 1.2.4-8081+ Fix from $2,3002020-10-29 HIGH 7.8 CVE-2020-16262 Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation. Winston Firmware No fix yet Fix from $1,9502020-10-28 HIGH 8.8 CVE-2020-7125 A remote escalation of privilege vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2. Airwave Glass 1.3.2+ Fix from $1,9502020-10-26 HIGH 7.8 CVE-2020-24848 FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local p… Fruitywifi after 2.4 Fix from $1,9502020-10-23 HIGH 7.8 CVE-2020-9112 Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability. Due to lack of privilege restrictions on some of… Taurus An00b Firmware 10.1.0.156+ Fix from $1,9502020-10-19 HIGH 7.8 CVE-2020-16940 <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who… Windows 10 Patch available Fix from $1,9502020-10-16 HIGH 7.8 CVE-2020-16902 <p>An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an … Windows 10 Patch available Fix from $1,9502020-10-16 HIGH 8.2 CVE-2020-7334 Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators … Application And Change Control 8.3.2+ Fix from $1,9502020-10-15 HIGH 8.8 CVE-2020-7330 Privilege Escalation vulnerability in McAfee Total Protection (MTP) trial prior to 4.0.176.1 allows local users to schedule tasks which call maliciou… Total Protection 4.0.176.1+ Fix from $1,9502020-10-14 MEDIUM 6.8 CVE-2020-15797 A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 r… Dca Vantage Analyzer Firmware 4.5.0.0+ Fix from $1,6002020-10-13 HIGH 7.8 CVE-2020-26880 Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration… Fedora after 6.2.56 Fix from $1,9502020-10-07 HIGH 8.8 CVE-2020-26596EPSS 6% The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to execute arbitrary code because o… Elementor Pro after 3.0.5 Fix from $1,9502020-10-07 MEDIUM 6.5 CVE-2020-8223 A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assi… Nextcloud Server No fix yet Fix from $1,6002020-10-05 HIGH 7.8 CVE-2020-3393 A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to r… Ios Xe Mitigation only Fix from $1,9502020-09-24