Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-21533 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2026-21533)
vulnerability in Microsoft windows (CVE-2026-21533). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-67246 |
|
Privilege Escalation in privilege-escalation (CVE-2025-67246)
vulnerability in privilege-escalation (CVE-2025-67246). Confidential information can be exposed externally.
|
| CVE-2025-59705 |
|
Privilege Escalation in entrust (CVE-2025-59705)
vulnerability in entrust (CVE-2025-59705). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `13.6.12` or later.
|
| CVE-2025-59697 |
|
Privilege Escalation in entrust (CVE-2025-59697)
vulnerability in entrust (CVE-2025-59697). Successful exploitation can lead to full system takeover.
|
| CVE-2025-59693 |
|
Privilege Escalation in entrust (CVE-2025-59693)
vulnerability in entrust (CVE-2025-59693). Successful exploitation can lead to full system takeover.
|
| CVE-2025-65621 |
|
Cross-Site Scripting (XSS) in privilege-escalation (CVE-2025-65621)
cross-site scripting in privilege-escalation (CVE-2025-65621). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-54821 |
|
Privilege Escalation in fortinet (CVE-2025-54821)
vulnerability in fortinet (CVE-2025-54821). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-50892 |
|
Privilege Escalation in privilege-escalation (CVE-2025-50892)
vulnerability in privilege-escalation (CVE-2025-50892). Successful exploitation can lead to full system takeover.
|
| CVE-2024-8068 KEV |
|
[KEV] Privilege Escalation in Citrix session-recording (CVE-2024-8068)
vulnerability in Citrix session-recording (CVE-2024-8068). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-50674 |
|
Vulnerability in openmediavault (CVE-2025-50674)
vulnerability in openmediavault (CVE-2025-50674). Successful exploitation can lead to full system takeover.
|
| CVE-2024-48729 |
|
Privilege Escalation in CVE-2024-48729 (CVE-2024-48729)
vulnerability in CVE-2024-48729 (CVE-2024-48729). Confidential information can be exposed externally.
|
| CVE-2025-4334 |
|
Privilege Escalation in wordpress (CVE-2025-4334)
vulnerability in wordpress (CVE-2025-4334). Successful exploitation can lead to full system takeover.
|
| CVE-2024-57062 |
|
Privilege Escalation in soundcloud (CVE-2024-57062)
vulnerability in soundcloud (CVE-2024-57062). Successful exploitation can lead to full system takeover.
|
| CVE-2024-49035 KEV |
|
[KEV] Privilege Escalation in Microsoft partner-center (CVE-2024-49035)
vulnerability in Microsoft partner-center (CVE-2024-49035). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-11218 |
|
Privilege Escalation in CVE-2024-11218 (CVE-2024-11218)
vulnerability in CVE-2024-11218 (CVE-2024-11218). Successful exploitation can lead to full system takeover. Exploitable via ``buildah.``.
|
| CVE-2024-52336 |
|
Privilege Escalation in privilege-escalation (CVE-2024-52336)
vulnerability in privilege-escalation (CVE-2024-52336). Successful exploitation can lead to full system takeover. Exploitable via ``script_pre``.
|
| CVE-2024-8424 |
|
Privilege Escalation in CVE-2024-8424 (CVE-2024-8424)
vulnerability in CVE-2024-8424 (CVE-2024-8424). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-45496 |
|
Privilege Escalation in CVE-2024-45496 (CVE-2024-45496)
vulnerability in CVE-2024-45496 (CVE-2024-45496). Confidential information can be exposed externally.
|
| CVE-2024-37980 |
|
Microsoft SQL Server Elevation of Privilege Vulnerability
Microsoft SQL Server Elevation of Privilege Vulnerability
|
| CVE-2024-38014 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2024-38014)
vulnerability in Microsoft windows (CVE-2024-38014). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-37858 |
|
SQL Injection in sqli (CVE-2024-37858)
SQL injection in sqli (CVE-2024-37858). Successful exploitation can lead to full system takeover.
|
| CVE-2023-37058 |
|
Privilege Escalation in unionman (CVE-2023-37058)
vulnerability in unionman (CVE-2023-37058). Successful exploitation can lead to full system takeover.
|
| CVE-2024-26169 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2024-26169)
vulnerability in Microsoft windows (CVE-2024-26169). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-33775 |
|
Privilege Escalation in nagios (CVE-2024-33775)
vulnerability in nagios (CVE-2024-33775). Successful exploitation can lead to full system takeover.
|
| CVE-2024-25343 |
|
Privilege Escalation in tenda (CVE-2024-25343)
vulnerability in tenda (CVE-2024-25343). Confidential information can be exposed externally.
|
| CVE-2024-22922 |
|
Privilege Escalation in projectworlds (CVE-2024-22922)
vulnerability in projectworlds (CVE-2024-22922). Successful exploitation can lead to full system takeover.
|
| CVE-2023-6507 |
|
Privilege Escalation in CVE-2023-6507 (CVE-2023-6507)
vulnerability in CVE-2023-6507 (CVE-2023-6507). Confidential information can be exposed externally. Exploitable via ``subprocess``.
|
| CVE-2023-28434 KEV |
|
[KEV] Privilege Escalation in minio (CVE-2023-28434)
vulnerability in minio (CVE-2023-28434). Risk of unauthorized operations or information disclosure. Exploitable via ``PostPolicyBucket``. Listed in CISA KEV — actively exploited.
|
| CVE-2023-4662 |
|
Vulnerability in adobe (CVE-2023-4662)
vulnerability in adobe (CVE-2023-4662). Successful exploitation can lead to full system takeover.
|
| CVE-2023-29819 |
|
Privilege Escalation in webroot (CVE-2023-29819)
vulnerability in webroot (CVE-2023-29819). Confidential information can be exposed externally.
|
| CVE-2023-26243 |
|
Path Traversal in hyundai (CVE-2023-26243)
path traversal in hyundai (CVE-2023-26243). Successful exploitation can lead to full system takeover.
|
| CVE-2023-26244 |
|
Privilege Escalation in hyundai (CVE-2023-26244)
vulnerability in hyundai (CVE-2023-26244). Successful exploitation can lead to full system takeover.
|
| CVE-2023-26245 |
|
Privilege Escalation in hyundai (CVE-2023-26245)
vulnerability in hyundai (CVE-2023-26245). Successful exploitation can lead to full system takeover.
|
| CVE-2023-26246 |
|
Privilege Escalation in hyundai (CVE-2023-26246)
vulnerability in hyundai (CVE-2023-26246). Successful exploitation can lead to full system takeover.
|
| CVE-2019-1388 KEV |
|
[KEV] Privilege Escalation in Microsoft windows (CVE-2019-1388)
vulnerability in Microsoft windows (CVE-2019-1388). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-45608 |
|
Privilege Escalation in thingsboard (CVE-2022-45608)
vulnerability in thingsboard (CVE-2022-45608). Successful exploitation can lead to full system takeover.
|
| CVE-2023-21777 |
|
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
|
| CVE-2021-25337 KEV |
|
[KEV] Privilege Escalation in Samsung mobile-devices (CVE-2021-25337)
vulnerability in Samsung mobile-devices (CVE-2021-25337). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-21046 |
|
Privilege Escalation in privilege-escalation (CVE-2020-21046)
vulnerability in privilege-escalation (CVE-2020-21046). Successful exploitation can lead to full system takeover.
|
| CVE-2014-3153 KEV |
|
[KEV] Privilege Escalation in Linux kernel (CVE-2014-3153)
vulnerability in Linux kernel (CVE-2014-3153). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-29333 |
|
Privilege Escalation in cyberlink (CVE-2022-29333)
vulnerability in cyberlink (CVE-2022-29333). Successful exploitation can lead to full system takeover.
|
| CVE-2020-27518 |
|
Privilege Escalation in privilege-escalation (CVE-2020-27518)
vulnerability in privilege-escalation (CVE-2020-27518). Successful exploitation can lead to full system takeover.
|
| CVE-2018-8044 |
|
Privilege Escalation in k7computing (CVE-2018-8044)
vulnerability in k7computing (CVE-2018-8044). Successful exploitation can lead to full system takeover.
|
| CVE-2018-9332 |
|
Privilege Escalation in k7computing (CVE-2018-9332)
vulnerability in k7computing (CVE-2018-9332). Successful exploitation can lead to full system takeover.
|
| CVE-2018-8724 |
|
Privilege Escalation in k7computing (CVE-2018-8724)
vulnerability in k7computing (CVE-2018-8724). Successful exploitation can lead to full system takeover.
|
| CVE-2018-9333 |
|
Vulnerability in k7computing (CVE-2018-9333)
vulnerability in k7computing (CVE-2018-9333). Successful exploitation can lead to full system takeover.
|
| CVE-2020-15368 |
|
Privilege Escalation in asrock (CVE-2020-15368)
vulnerability in asrock (CVE-2020-15368). Data can be tampered with by attackers.
|
| CVE-2019-12794 |
|
Privilege Escalation in misp-project (CVE-2019-12794)
vulnerability in misp-project (CVE-2019-12794). Successful exploitation can lead to full system takeover.
|
| CVE-2016-10010 |
|
Vulnerability in c (CVE-2016-10010)
vulnerability in c (CVE-2016-10010). Successful exploitation can lead to full system takeover.
|
| CVE-2022-20759 |
|
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authen...
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is...
|