Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Snipe It MEDIUM 6.5
CVE-2026-55843

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through Normal…

Fix: 8.6.0+
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.1
CVE-2026-51119

An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-40009

Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by re…

Mitigation only
Fix from $1,600 2026-07-10
Discourse HIGH 7.1
CVE-2026-44787

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered us…

Fix: 2026.1.5 / 2026.4.2+
Fix from $1,950 2026-07-09
Prisma Browser MEDIUM 6.7
CVE-2026-0275

A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macO…

Fix: 149.10.3.53+
Fix from $1,600 2026-07-09
Cortex Xdr Broker Vm HIGH 7.8
CVE-2026-0276

A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root …

Fix: 31.0.58+
Fix from $1,950 2026-07-09
Unclassified HIGH 8.1
CVE-2026-54652

Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the…

Patch available
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.3
CVE-2026-14250

The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to t…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified HIGH 7.5
CVE-2026-9842

The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This i…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.8
CVE-2026-14482

The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The vulnerability exists d…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.1
CVE-2026-58583

FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user a…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 8.5
CVE-2026-53645

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged staff account to grant arbitr…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 7.3
CVE-2026-14719

A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file r…

Mitigation only
Fix from $1,950 2026-07-05
Containerd HIGH 7.8
CVE-2026-46680

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directiv…

Fix: 1.7.32 / 2.0.9+
Fix from $1,950 2026-07-01
Unclassified HIGH 8.8
CVE-2026-13228

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in ve…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 8.8
CVE-2026-12224

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 8.8
CVE-2026-57995

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to gr…

Mitigation only
Fix from $1,950 2026-06-30
Chrome HIGH 7.8
CVE-2026-14124

Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level pr…

Fix: 150.0.7871.47+
Fix from $1,950 2026-06-30
Chrome CRITICAL 9.6
CVE-2026-14101

Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer …

Fix: 150.0.7871.47+
Fix from $2,300 2026-06-30
Mantaray Nm HIGH 7.8
CVE-2025-7406

Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privilege…

Fix: 25R2-NM+
Fix from $1,950 2026-06-30
Unclassified CRITICAL 9.9
CVE-2026-58053

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig …

Mitigation only
Fix from $2,300 2026-06-28
Unclassified HIGH 7.2
CVE-2026-58054

MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers th…

Mitigation only
Fix from $1,950 2026-06-28
Unclassified CRITICAL 9.8
CVE-2026-12415

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account…

Mitigation only
Fix from $2,300 2026-06-27
FreeBSD MEDIUM 5.5
CVE-2026-45256

When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation was permitted but did not ch…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 7.1
CVE-2026-52808

Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 8.2
CVE-2026-56245

Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time RPC function that allows unau…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.3
CVE-2026-56225

Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers (get/put/delete/post). API keys create…

Mitigation only
Fix from $1,950 2026-06-23
Openshift Container Platform HIGH 8.8
CVE-2026-54099

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a …

Fix: 4.22.1+
Fix from $1,950 2026-06-22
Unclassified HIGH 8.8
CVE-2026-8157

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API …

Mitigation only
Fix from $1,950 2026-06-22
Unclassified HIGH 7.6
CVE-2026-56239

Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY DEFINER function, which perf…

Mitigation only
Fix from $1,950 2026-06-21