Show filters
31,494 Total Results
Displaying 1-10 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Very High
CVE-2021-3156 "Baron Samedit"
Disclosure Date: January 26, 2021 (last updated November 08, 2023)
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
12
Attacker Value
High
CVE-2020-17087 Windows Kernel local privilege escalation 0day
Disclosure Date: November 11, 2020 (last updated October 07, 2023)
Windows Kernel Local Elevation of Privilege Vulnerability
12
Attacker Value
Very High
CVE-2021-36934 Windows Elevation of Privilege
Disclosure Date: July 22, 2021 (last updated October 07, 2023)
Windows Elevation of Privilege Vulnerability
7
Attacker Value
High
CVE-2021-4034
Disclosure Date: January 28, 2022 (last updated October 07, 2023)
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
5
Attacker Value
Very High
CVE-2021-24085
Disclosure Date: February 25, 2021 (last updated October 07, 2023)
Microsoft Exchange Server Spoofing Vulnerability This CVE ID is unique from CVE-2021-1730.
6
Attacker Value
Low
CVE-2021-1647 Microsoft Windows Defender Zero-Day Vulnerability
Disclosure Date: January 12, 2021 (last updated October 07, 2023)
Microsoft Defender Remote Code Execution Vulnerability
6
Attacker Value
Low
CVE-2019-14287
Disclosure Date: October 17, 2019 (last updated November 08, 2023)
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
1
Attacker Value
High
CVE-2021-21551
Disclosure Date: May 04, 2021 (last updated October 09, 2023)
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.
5
Attacker Value
Very High
CVE-2020-1337
Disclosure Date: August 17, 2020 (last updated October 07, 2023)
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'.
5
Attacker Value
Moderate
CVE-2023-22952
Disclosure Date: January 11, 2023 (last updated October 08, 2023)
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
3