Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-2914 CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation d… Endpoint Privilege Manager 25.11.0+ Fix from $1,9502026-02-25 HIGH 7.8 CVE-2025-66374 CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administ… Endpoint Privilege Manager after 25.10.0 Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2025-49831 An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can r… Conjur 1.22.1 / 13.5.1+ Fix from $2,3002025-07-15 MEDIUM 6.5 CVE-2025-49829 Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets Manager, Self-Hosted allows authentica… Conjur 1.22.1 / 13.5.1+ Fix from $1,6002025-07-15 MEDIUM 6.5 CVE-2025-49830 Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who is able to load policy can use the poli… Conjur 1.22.1 / 13.5.1+ Fix from $1,6002025-07-15 CRITICAL 9.8 CVE-2025-49827 Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22.0 and Secrets Manager, Self-H… Conjur 1.22.1 / 13.5.1+ Fix from $2,3002025-07-15 HIGH 8.8 CVE-2025-49828 Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-H… Conjur 1.21.2 / 13.5+ Fix from $1,9502025-07-15 MEDIUM 6.1 CVE-2024-54840 PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can … Privileged Access Manager 14.4+ Fix from $1,6002025-02-03 MEDIUM 6.5 CVE-2024-42337 CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor Identity No fix yet Fix from $1,6002024-08-25 HIGH 7.8 CVE-2017-11197 In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add prin… Viewfinity 6.1.1.220+ Fix from $1,9502023-05-03 MEDIUM 5.3 CVE-2022-22700 CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain conf… Identity after 22.1 Fix from $1,6002022-03-03 HIGH 7.8 CVE-2021-44049 CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Pro… Endpoint Privilege Manager 11.5.4.355 / 11.5.4.500+ Fix from $1,9502022-01-15 HIGH 7.5 CVE-2021-31796 An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may rea… Credential Provider 12.1+ Fix from $1,9502021-09-02 MEDIUM 5.1 CVE-2021-31797 The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to passwo… Credential Provider 12.1+ Fix from $1,6002021-09-02 MEDIUM 5.3 CVE-2021-37151 CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authenticati… Identity 21.11.133+ Fix from $1,6002021-09-01 MEDIUM 5.5 CVE-2020-25738 CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a pro… Endpoint Privilege Manager No fix yet Fix from $1,6002020-11-27 CRITICAL 9.0 CVE-2020-4062 In Conjur OSS Helm Chart before 2.0.0, a recently identified critical vulnerability resulted in the installation of the Conjur Postgres database with… Conjur Oss Helm Chart 2.0.0+ Fix from $2,3002020-06-22 CRITICAL 9.8 CVE-2019-7442EPSS 40% An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attacke… Enterprise Password Vault after 10.7 Fix from $2,3002019-05-08 HIGH 7.8 CVE-2018-14894 CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file) to bypass intended access r… Endpoint Privilege Manager after 10.2.1.603 Fix from $1,9502019-04-09 HIGH 7.0 CVE-2019-9627 A buffer overflow in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10.7 allows an attacker (without… Endpoint Privilege Manager 10.7+ Fix from $1,9502019-03-08 CRITICAL 9.8 CVE-2018-13052 In CyberArk Endpoint Privilege Manager (formerly Viewfinity), Privilege Escalation is possible if the attacker has one process that executes as Admin. Endpoint Privilege Manager No fix yet Fix from $2,3002018-07-05 MEDIUM 5.4 CVE-2018-12903 In CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token screen, the … Endpoint Privilege Manager No fix yet Fix from $1,6002018-06-26 CRITICAL 9.8 CVE-2018-9843EPSS 17% The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serializ… Password Vault 9.9.5 / 10.1+ Fix from $2,3002018-04-12 MEDIUM 5.3 CVE-2018-9842EPSS 16% CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message. Password Vault 9.7+ Fix from $1,6002018-04-12