Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
HIGH 8.8 CVE-2025-69138 Subscriber Privilege Escalation in Genemy <= 1.6.6 versions. Mitigation only Fix from $1,9502026-06-17 HIGH 8.8 CVE-2025-59563 Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions. Mitigation only Fix from $1,9502026-06-17 MEDIUM 5.4 CVE-2026-53862 OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader req… Openclaw 2026.5.12+ Fix from $1,6002026-06-16 MEDIUM 5.4 CVE-2026-53847 OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gateway operators with operator.w… Openclaw 2026.5.6+ Fix from $1,6002026-06-16 HIGH 8.8 CVE-2026-12289 Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thund… Firefox 115.37.0 / 140.12.0+ Fix from $1,9502026-06-16 CRITICAL 9.6 CVE-2026-12294 Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, a… Firefox 115.37.0 / 140.12.0+ Fix from $2,3002026-06-16 HIGH 8.8 CVE-2026-49780 Customer Privilege Escalation in Dokan <= 5.0.2 versions. No fix yet Fix from $1,9502026-06-15 HIGH 7.5 CVE-2026-49083 Contributor Privilege Escalation in LatePoint <= 5.5.1 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.3 CVE-2026-49063 Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions. No fix yet Fix from $1,9502026-06-15 HIGH 8.8 CVE-2026-48889 Subscriber Privilege Escalation in Amelia <= 2.3 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 8.8 CVE-2026-39579 Contributor Privilege Escalation in B Blocks <= 2.0.31 versions. Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.8 CVE-2026-39583 Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions. Mitigation only Fix from $2,3002026-06-15 HIGH 8.1 CVE-2026-39587 Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions. Mitigation only Fix from $1,9502026-06-15 HIGH 7.2 CVE-2026-39470 Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions. Mitigation only Fix from $1,9502026-06-15 CRITICAL 9.8 CVE-2026-34901 Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions. Mitigation only Fix from $2,3002026-06-15 HIGH 7.2 CVE-2026-27407 Editor Privilege Escalation in AI Engine <= 3.4.9 versions. No fix yet Fix from $1,9502026-06-15 HIGH 8.8 CVE-2026-49111 Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a… Mitigation only Fix from $1,9502026-06-15 HIGH 7.8 CVE-2026-12217 A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the library dvdfabio.sys of the compon… Mitigation only Fix from $1,9502026-06-15 MEDIUM 5.3 CVE-2026-12201 A flaw has been found in IObit Malware Fighter up to 13.2.0. Affected by this vulnerability is an unknown functionality of the component DLL Handler.… Mitigation only Fix from $1,6002026-06-15 MEDIUM 5.3 CVE-2026-44173 MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11… MariaDB 10.6.26 / 10.11.17+ Fix from $1,6002026-06-12 HIGH 8.8 CVE-2026-45830 A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, writ… Chromadb after 1.5.9 Fix from $1,9502026-06-12 CRITICAL 9.8 CVE-2026-49060 Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App … Mitigation only Fix from $2,3002026-06-11 HIGH 8.3 CVE-2026-53814 OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback… Openclaw 2026.5.20+ Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-47169 Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a user with Manage Server / Manage… Mitigation only Fix from $1,9502026-06-11 HIGH 7.8 CVE-2026-45490 Improper authorization in .NET allows an authorized attacker to elevate privileges locally. .net 8.0.28 / 9.0.17+ Fix from $1,9502026-06-09 CRITICAL 9.1 CVE-2025-10263 Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Corte… Mitigation only Fix from $2,3002026-06-09 MEDIUM 5.3 CVE-2026-11620 A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsf… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.3 CVE-2026-11619 A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/c… Patch available Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-11555 A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the componen… Dgs 1100 08pd Firmware Mitigation only Fix from $1,9502026-06-08 MEDIUM 6.3 CVE-2026-11532 A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function … Mitigation only Fix from $1,6002026-06-08