Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified MEDIUM 5.1
CVE-2026-15380

A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory c…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.1
CVE-2026-15379

The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the…

No fix yet
Fix from $1,600 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-9810

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator …

Mitigation only
Fix from $2,300 2026-07-17
Unclassified HIGH 8.1
CVE-2026-11961

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is …

Mitigation only
Fix from $1,950 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-15982

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in al…

Mitigation only
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-14956

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper val…

No fix yet
Fix from $2,300 2026-07-17
Unclassified HIGH 8.1
CVE-2026-43978

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged …

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-36425

An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.5
CVE-2026-6423

A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authentication in an IPC channel.

Mitigation only
Fix from $1,950 2026-07-16
Unclassified HIGH 8.8
CVE-2026-15103

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitr…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.8
CVE-2026-13741

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,…

Mitigation only
Fix from $1,950 2026-07-16
Unclassified HIGH 8.8
CVE-2026-12525

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing …

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.6
CVE-2026-53444

Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.4
CVE-2026-62355

TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine …

Mitigation only
Fix from $1,600 2026-07-15
Better Auth\/sso HIGH 7.1
CVE-2026-53515

Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register…

Fix: 1.6.11+
Fix from $1,950 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-14960

Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified MEDIUM 6.2
CVE-2026-14961

Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sensitive IOCTL functionality. T…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 8.8
CVE-2026-57996

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create …

Mitigation only
Fix from $1,950 2026-07-15
Powerscale Onefs MEDIUM 6.7
CVE-2026-49501

Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerabili…

Fix: 9.10.1.8 / 9.13.1.0+
Fix from $1,600 2026-07-15
Windows 10 1607 HIGH 7.8
CVE-2026-50391

Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-50343

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 11 24h2 MEDIUM 5.5
CVE-2026-50295

Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49176

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Unclassified HIGH 8.5
CVE-2026-53565

Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This iss…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-52533

An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file

No fix yet
Fix from $2,300 2026-07-13
Unclassified HIGH 8.8
CVE-2026-61463

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without…

Patch available
Fix from $1,950 2026-07-13
Apache Airflow Providers Fab HIGH 8.1
CVE-2026-59245

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resour…

Fix: 3.7.2+
Fix from $1,950 2026-07-13
Unclassified HIGH 8.8
CVE-2026-59260

OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon wi…

Mitigation only
Fix from $1,950 2026-07-12
Unclassified HIGH 8.8
CVE-2026-14262

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation i…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified HIGH 8.8
CVE-2026-13756

The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing au…

Mitigation only
Fix from $1,950 2026-07-11