Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-46310 |
|
Privilege Escalation in apple (CVE-2025-46310)
vulnerability in apple (CVE-2025-46310). Data can be tampered with by attackers.
|
| CVE-2026-21533 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2026-21533)
vulnerability in Microsoft windows (CVE-2026-21533). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-67246 |
|
Privilege Escalation in privilege-escalation (CVE-2025-67246)
vulnerability in privilege-escalation (CVE-2025-67246). Confidential information can be exposed externally.
|
| CVE-2025-59705 |
|
Privilege Escalation in entrust (CVE-2025-59705)
vulnerability in entrust (CVE-2025-59705). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `13.6.12` or later.
|
| CVE-2025-59697 |
|
Privilege Escalation in entrust (CVE-2025-59697)
vulnerability in entrust (CVE-2025-59697). Successful exploitation can lead to full system takeover.
|
| CVE-2025-59693 |
|
Privilege Escalation in entrust (CVE-2025-59693)
vulnerability in entrust (CVE-2025-59693). Successful exploitation can lead to full system takeover.
|
| CVE-2025-65621 |
|
Cross-Site Scripting (XSS) in privilege-escalation (CVE-2025-65621)
cross-site scripting in privilege-escalation (CVE-2025-65621). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-54821 |
|
Privilege Escalation in fortinet (CVE-2025-54821)
vulnerability in fortinet (CVE-2025-54821). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-50892 |
|
Privilege Escalation in privilege-escalation (CVE-2025-50892)
vulnerability in privilege-escalation (CVE-2025-50892). Successful exploitation can lead to full system takeover.
|
| CVE-2024-8068 KEV |
|
[KEV] Privilege Escalation in Citrix session-recording (CVE-2024-8068)
vulnerability in Citrix session-recording (CVE-2024-8068). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-50674 |
|
Vulnerability in openmediavault (CVE-2025-50674)
vulnerability in openmediavault (CVE-2025-50674). Successful exploitation can lead to full system takeover.
|
| CVE-2024-48729 |
|
Privilege Escalation in CVE-2024-48729 (CVE-2024-48729)
vulnerability in CVE-2024-48729 (CVE-2024-48729). Confidential information can be exposed externally.
|
| CVE-2025-4334 |
|
Privilege Escalation in wordpress (CVE-2025-4334)
vulnerability in wordpress (CVE-2025-4334). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57062 |
|
Privilege Escalation in soundcloud (CVE-2024-57062)
vulnerability in soundcloud (CVE-2024-57062). Successful exploitation can lead to full system takeover.
|
| CVE-2024-49035 KEV |
|
[KEV] Privilege Escalation in Microsoft partner-center (CVE-2024-49035)
vulnerability in Microsoft partner-center (CVE-2024-49035). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-11218 |
|
Privilege Escalation in CVE-2024-11218 (CVE-2024-11218)
vulnerability in CVE-2024-11218 (CVE-2024-11218). Successful exploitation can lead to full system takeover. Exploitable via ``buildah.``.
|
| CVE-2024-52336 |
|
Privilege Escalation in privilege-escalation (CVE-2024-52336)
vulnerability in privilege-escalation (CVE-2024-52336). Successful exploitation can lead to full system takeover. Exploitable via ``script_pre``.
|
| CVE-2024-8424 |
|
Privilege Escalation in CVE-2024-8424 (CVE-2024-8424)
vulnerability in CVE-2024-8424 (CVE-2024-8424). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-45496 |
|
Privilege Escalation in CVE-2024-45496 (CVE-2024-45496)
vulnerability in CVE-2024-45496 (CVE-2024-45496). Confidential information can be exposed externally.
|
| CVE-2024-37980 |
|
Microsoft SQL Server Elevation of Privilege Vulnerability
Microsoft SQL Server Elevation of Privilege Vulnerability
|
| CVE-2024-38014 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2024-38014)
vulnerability in Microsoft windows (CVE-2024-38014). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-37858 |
|
SQL Injection in sqli (CVE-2024-37858)
SQL injection in sqli (CVE-2024-37858). Successful exploitation can lead to full system takeover.
|
| CVE-2023-37058 |
|
Privilege Escalation in unionman (CVE-2023-37058)
vulnerability in unionman (CVE-2023-37058). Successful exploitation can lead to full system takeover.
|
| CVE-2024-26169 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2024-26169)
vulnerability in Microsoft windows (CVE-2024-26169). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-33775 |
|
Privilege Escalation in nagios (CVE-2024-33775)
vulnerability in nagios (CVE-2024-33775). Successful exploitation can lead to full system takeover.
|
| CVE-2024-25343 |
|
Privilege Escalation in tenda (CVE-2024-25343)
vulnerability in tenda (CVE-2024-25343). Confidential information can be exposed externally.
|
| CVE-2024-22922 |
|
Privilege Escalation in projectworlds (CVE-2024-22922)
vulnerability in projectworlds (CVE-2024-22922). Successful exploitation can lead to full system takeover.
|
| CVE-2023-6507 |
|
Privilege Escalation in CVE-2023-6507 (CVE-2023-6507)
vulnerability in CVE-2023-6507 (CVE-2023-6507). Confidential information can be exposed externally. Exploitable via ``subprocess``.
|
| CVE-2023-28434 KEV |
|
[KEV] Privilege Escalation in minio (CVE-2023-28434)
vulnerability in minio (CVE-2023-28434). Risk of unauthorized operations or information disclosure. Exploitable via ``PostPolicyBucket``. Listed in CISA KEV — actively exploited.
|
| CVE-2023-4662 |
|
Vulnerability in adobe (CVE-2023-4662)
vulnerability in adobe (CVE-2023-4662). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29819 |
|
Privilege Escalation in webroot (CVE-2023-29819)
vulnerability in webroot (CVE-2023-29819). Confidential information can be exposed externally.
|
| CVE-2023-26243 |
|
Path Traversal in hyundai (CVE-2023-26243)
path traversal in hyundai (CVE-2023-26243). Successful exploitation can lead to full system takeover.
|
| CVE-2023-26244 |
|
Privilege Escalation in hyundai (CVE-2023-26244)
vulnerability in hyundai (CVE-2023-26244). Successful exploitation can lead to full system takeover.
|
| CVE-2023-26245 |
|
Privilege Escalation in hyundai (CVE-2023-26245)
vulnerability in hyundai (CVE-2023-26245). Successful exploitation can lead to full system takeover.
|
| CVE-2023-26246 |
|
Privilege Escalation in hyundai (CVE-2023-26246)
vulnerability in hyundai (CVE-2023-26246). Successful exploitation can lead to full system takeover.
|
| CVE-2019-1388 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2019-1388)
vulnerability in Microsoft windows (CVE-2019-1388). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-45608 |
|
Privilege Escalation in thingsboard (CVE-2022-45608)
vulnerability in thingsboard (CVE-2022-45608). Successful exploitation can lead to full system takeover.
|
| CVE-2023-21777 |
|
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
|
| CVE-2021-25337 KEV |
|
[KEV] Privilege Escalation in Samsung mobile-devices (CVE-2021-25337)
vulnerability in Samsung mobile-devices (CVE-2021-25337). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-21046 |
|
Privilege Escalation in privilege-escalation (CVE-2020-21046)
vulnerability in privilege-escalation (CVE-2020-21046). Successful exploitation can lead to full system takeover.
|
| CVE-2014-3153 KEV |
|
[KEV] Privilege Escalation in Linux kernel (CVE-2014-3153)
vulnerability in Linux kernel (CVE-2014-3153). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-29333 |
|
Privilege Escalation in cyberlink (CVE-2022-29333)
vulnerability in cyberlink (CVE-2022-29333). Successful exploitation can lead to full system takeover.
|
| CVE-2020-27518 |
|
Privilege Escalation in privilege-escalation (CVE-2020-27518)
vulnerability in privilege-escalation (CVE-2020-27518). Successful exploitation can lead to full system takeover.
|
| CVE-2018-8044 |
|
Privilege Escalation in k7computing (CVE-2018-8044)
vulnerability in k7computing (CVE-2018-8044). Successful exploitation can lead to full system takeover.
|
| CVE-2018-9332 |
|
Privilege Escalation in k7computing (CVE-2018-9332)
vulnerability in k7computing (CVE-2018-9332). Successful exploitation can lead to full system takeover.
|
| CVE-2018-8724 |
|
Privilege Escalation in k7computing (CVE-2018-8724)
vulnerability in k7computing (CVE-2018-8724). Successful exploitation can lead to full system takeover.
|
| CVE-2018-9333 |
|
Vulnerability in k7computing (CVE-2018-9333)
vulnerability in k7computing (CVE-2018-9333). Successful exploitation can lead to full system takeover.
|
| CVE-2020-15368 |
|
Privilege Escalation in asrock (CVE-2020-15368)
vulnerability in asrock (CVE-2020-15368). Data can be tampered with by attackers.
|
| CVE-2019-12794 |
|
Privilege Escalation in misp-project (CVE-2019-12794)
vulnerability in misp-project (CVE-2019-12794). Successful exploitation can lead to full system takeover.
|
| CVE-2016-10010 |
|
Vulnerability in c (CVE-2016-10010)
vulnerability in c (CVE-2016-10010). Successful exploitation can lead to full system takeover.
|