Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Mysql Server MEDIUM 6.4
CVE-2026-60183

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Clone Plugin). Supported versions that are affected are…

Fix: after 8.4.10
Fix from $1,600 2026-07-21
Database Server HIGH 8.8
CVE-2026-60175

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2.…

Fix: after 23.26.2
Fix from $1,950 2026-07-21
Vm Virtualbox MEDIUM 6.1
CVE-2026-60162

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Dif…

No fix yet
Fix from $1,600 2026-07-21
Vm Virtualbox HIGH 7.8
CVE-2026-60150

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Eas…

No fix yet
Fix from $1,950 2026-07-21
Weblogic Server HIGH 7.2
CVE-2026-60153

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.…

No fix yet
Fix from $1,950 2026-07-21
Vm Virtualbox HIGH 7.8
CVE-2026-47054

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Eas…

No fix yet
Fix from $1,950 2026-07-21
Vm Virtualbox HIGH 7.8
CVE-2026-47047

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Eas…

No fix yet
Fix from $1,950 2026-07-21
Enterprise Manager Base Platform HIGH 8.8
CVE-2026-46995

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions t…

No fix yet
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.6
CVE-2026-47413

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenan…

Mitigation only
Fix from $2,300 2026-07-21
Unclassified CRITICAL 9.6
CVE-2026-47416

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege esc…

No fix yet
Fix from $2,300 2026-07-21
Unclassified MEDIUM 6.5
CVE-2026-47411

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling wo…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 8.1
CVE-2026-47412

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling de…

No fix yet
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.4
CVE-2026-47407

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources un…

No fix yet
Fix from $2,300 2026-07-21
Unclassified HIGH 8.1
CVE-2026-47409

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling ow…

No fix yet
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16401

Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16396

Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16379

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and T…

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16371

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderb…

Fix: 140.13.0 / 153.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16372

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16365

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Firefox HIGH 8.8
CVE-2026-16366

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-13439

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, a…

No fix yet
Fix from $2,300 2026-07-21
Unclassified HIGH 7.1
CVE-2026-55550

NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal appli…

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-16337

Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a …

No fix yet
Fix from $2,300 2026-07-20
Request Tracker CRITICAL 9.1
CVE-2026-44231

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an informa…

Fix: 5.0.10 / 6.0.3+
Fix from $2,300 2026-07-20
Syncope CRITICAL 9.8
CVE-2026-62183

Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user wor…

Fix: 4.0.7 / 4.1.2+
Fix from $2,300 2026-07-20
Unclassified HIGH 8.1
CVE-2026-13142

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its …

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.8
CVE-2026-47868

VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privil…

No fix yet
Fix from $1,950 2026-07-18
Unclassified HIGH 7.1
CVE-2026-47870

VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute rem…

No fix yet
Fix from $1,950 2026-07-18
Unclassified MEDIUM 6.5
CVE-2026-48010

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserControl…

No fix yet
Fix from $1,600 2026-07-17