Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Endpoint Privilege Manager HIGH 7.8
CVE-2026-2914

CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation d…

Fix: 25.11.0+
Fix from $1,950 2026-02-25
Endpoint Privilege Manager HIGH 7.8
CVE-2025-66374

CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administ…

Fix: after 25.10.0
Fix from $1,950 2026-02-03
Conjur CRITICAL 9.8
CVE-2025-49831

An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can r…

Fix: 1.22.1 / 13.5.1+
Fix from $2,300 2025-07-15
Conjur MEDIUM 6.5
CVE-2025-49829

Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets Manager, Self-Hosted allows authentica…

Fix: 1.22.1 / 13.5.1+
Fix from $1,600 2025-07-15
Conjur MEDIUM 6.5
CVE-2025-49830

Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who is able to load policy can use the poli…

Fix: 1.22.1 / 13.5.1+
Fix from $1,600 2025-07-15
Conjur CRITICAL 9.8
CVE-2025-49827

Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22.0 and Secrets Manager, Self-H…

Fix: 1.22.1 / 13.5.1+
Fix from $2,300 2025-07-15
Conjur HIGH 8.8
CVE-2025-49828

Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-H…

Fix: 1.21.2 / 13.5+
Fix from $1,950 2025-07-15
Privileged Access Manager MEDIUM 6.1
CVE-2024-54840

PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can …

Fix: 14.4+
Fix from $1,600 2025-02-03
Identity MEDIUM 6.5
CVE-2024-42337

CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $1,600 2024-08-25
Viewfinity HIGH 7.8
CVE-2017-11197

In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add prin…

Fix: 6.1.1.220+
Fix from $1,950 2023-05-03
Identity MEDIUM 5.3
CVE-2022-22700

CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain conf…

Fix: after 22.1
Fix from $1,600 2022-03-03
Endpoint Privilege Manager HIGH 7.8
CVE-2021-44049

CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Pro…

Fix: 11.5.4.355 / 11.5.4.500+
Fix from $1,950 2022-01-15
Credential Provider HIGH 7.5
CVE-2021-31796

An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may rea…

Fix: 12.1+
Fix from $1,950 2021-09-02
Credential Provider MEDIUM 5.1
CVE-2021-31797

The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to passwo…

Fix: 12.1+
Fix from $1,600 2021-09-02
Identity MEDIUM 5.3
CVE-2021-37151

CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authenticati…

Fix: 21.11.133+
Fix from $1,600 2021-09-01
Endpoint Privilege Manager MEDIUM 5.5
CVE-2020-25738

CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a pro…

No fix yet
Fix from $1,600 2020-11-27
Conjur Oss Helm Chart CRITICAL 9.0
CVE-2020-4062

In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with…

Fix: 2.0.0+
Fix from $2,300 2020-06-22
Enterprise Password Vault CRITICAL 9.8
CVE-2019-7442EPSS 40%

An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attacke…

Fix: after 10.7
Fix from $2,300 2019-05-08
Endpoint Privilege Manager HIGH 7.8
CVE-2018-14894

CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file) to bypass intended access r…

Fix: after 10.2.1.603
Fix from $1,950 2019-04-09
Endpoint Privilege Manager HIGH 7.0
CVE-2019-9627

A buffer overflow in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7 allows an attacker (without…

Fix: 10.7+
Fix from $1,950 2019-03-08
Endpoint Privilege Manager CRITICAL 9.8
CVE-2018-13052

In CyberArk Endpoint Privilege Manager (formerly Viewfinity), Privilege Escalation is possible if the attacker has one process that executes as Admin.

No fix yet
Fix from $2,300 2018-07-05
Endpoint Privilege Manager MEDIUM 5.4
CVE-2018-12903

In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the …

No fix yet
Fix from $1,600 2018-06-26
Password Vault CRITICAL 9.8
CVE-2018-9843EPSS 17%

The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serializ…

Fix: 9.9.5 / 10.1+
Fix from $2,300 2018-04-12
Password Vault MEDIUM 5.3
CVE-2018-9842EPSS 16%

CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message.

Fix: 9.7+
Fix from $1,600 2018-04-12