Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
CRITICAL 9.1 CVE-2026-22908 Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confi… Tdc X401gl Firmware 1.4.0+ Fix from $2,3002026-01-15 CRITICAL 9.8 CVE-2026-23550EPSS 21% Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: fr… Mitigation only Fix from $2,3002026-01-14 MEDIUM 6.2 CVE-2022-50927 Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user … No fix yet Fix from $1,6002026-01-13 HIGH 7.7 CVE-2026-20852 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.7 CVE-2026-20804 Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 MEDIUM 6.5 CVE-2025-67278 An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request Tim Flow 9.1.2+ Fix from $1,6002026-01-09 MEDIUM 5.3 CVE-2025-67279 An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application stores pass… Tim Flow 9.1.2+ Fix from $1,6002026-01-09 HIGH 8.8 CVE-2025-31643 Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPCHURCH: from n/a through 2.7.0. Mitigation only Fix from $1,9502026-01-07 HIGH 8.8 CVE-2025-29004 Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing … Mitigation only Fix from $1,9502026-01-06 HIGH 8.8 CVE-2026-0574 A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file… Warehouse after 2025-10-06 Fix from $1,9502026-01-04 HIGH 7.5 CVE-2025-15126 A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position… Jeecg Boot after 3.9.0 Fix from $1,9502025-12-28 HIGH 8.1 CVE-2025-15085 A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/… Youlai Mall Mitigation only Fix from $1,9502025-12-25 CRITICAL 9.8 CVE-2019-25249 devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the html… Mitigation only Fix from $2,3002025-12-24 HIGH 8.8 CVE-2018-25148 Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to cr… Ipn4g Firmware No fix yet Fix from $1,9502025-12-24 MEDIUM 6.3 CVE-2025-14889 A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admi… Advanced Voting Management System No fix yet Fix from $1,6002025-12-18 CRITICAL 9.8 CVE-2025-64188 Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through … Mitigation only Fix from $2,3002025-12-18 HIGH 8.8 CVE-2025-59134 Incorrect Privilege Assignment vulnerability in Jthemes Sale! Immigration law, Visa services support, Migration Agent Consulting immiex allows Privil… Mitigation only Fix from $1,9502025-12-18 HIGH 8.8 CVE-2025-58710 Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation.This issue affects Hotel Listing: f… Mitigation only Fix from $1,9502025-12-18 HIGH 7.2 CVE-2025-55707 Incorrect Privilege Assignment vulnerability in WPXPO PostX ultimate-post allows Privilege Escalation.This issue affects PostX: from n/a through <= 4… Mitigation only Fix from $1,9502025-12-18 HIGH 7.2 CVE-2025-49379 Incorrect Privilege Assignment vulnerability in silverplugins217 Custom Fields Account Registration For Woocommerce custom-fields-account-registratio… Mitigation only Fix from $1,9502025-12-18 MEDIUM 5.4 CVE-2025-14748 A vulnerability was determined in Ningyuanda TC155 57.0.2.0. This affects an unknown function of the file /onvif/device_service of the component ONVI… Tc155 Firmware No fix yet Fix from $1,6002025-12-16 HIGH 8.8 CVE-2025-14749 A vulnerability was identified in Ningyuanda TC155 57.0.2.0. This impacts an unknown function of the file /onvif/device_service of the component ONVI… Tc155 Firmware No fix yet Fix from $1,9502025-12-16 HIGH 7.2 CVE-2025-14503 An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via ro… Harmonix 0.4.2+ Fix from $1,9502025-12-15 CRITICAL 9.1 CVE-2025-13888 A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated per… Patch available Fix from $2,3002025-12-15 MEDIUM 5.6 CVE-2025-14660 A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mc… Patch available Fix from $1,6002025-12-14 HIGH 8.4 CVE-2025-65807 An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command. Sd after 1.0.0 Fix from $1,9502025-12-10 HIGH 7.5 CVE-2025-14206 A vulnerability was determined in SourceCodester Online Student Clearance System 1.0. The affected element is an unknown function of the file /Admin/… Online Student Clearance System No fix yet Fix from $1,9502025-12-08 MEDIUM 6.3 CVE-2025-14089 A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the file /api/admin/update_account/ … Mitigation only Fix from $1,6002025-12-05 MEDIUM 6.3 CVE-2025-14088 A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of the file /je/load. This mani… No fix yet Fix from $1,6002025-12-05 HIGH 8.8 CVE-2025-14086 A vulnerability was found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is an unknown function of the file /app-api/v1/members/openid/. The manipul… Youlai Mall No fix yet Fix from $1,9502025-12-05