Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified CRITICAL 9.0
CVE-2026-10868

A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::…

Patch available
Fix from $2,300 2026-06-04
Connect M6e 5g Firmware HIGH 7.8
CVE-2026-49189

Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.

Mitigation only
Fix from $1,950 2026-06-04
Unclassified CRITICAL 9.8
CVE-2026-8206

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in al…

Mitigation only
Fix from $2,300 2026-06-02
Android MEDIUM 6.8
CVE-2026-0086

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to loca…

Mitigation only
Fix from $1,600 2026-06-01
Android HIGH 7.8
CVE-2026-0089

In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This cou…

Mitigation only
Fix from $1,950 2026-06-01
Android HIGH 7.8
CVE-2026-0091

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local…

Mitigation only
Fix from $1,950 2026-06-01
Android MEDIUM 6.2
CVE-2026-0046

In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This c…

Mitigation only
Fix from $1,600 2026-06-01
Android MEDIUM 6.8
CVE-2026-0048

In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead…

Mitigation only
Fix from $1,600 2026-06-01
Android MEDIUM 6.2
CVE-2026-0055

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory du…

Mitigation only
Fix from $1,600 2026-06-01
Android HIGH 7.8
CVE-2026-0009

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no addi…

Mitigation only
Fix from $1,950 2026-06-01
Unclassified MEDIUM 6.3
CVE-2026-10217

A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.g…

Mitigation only
Fix from $1,600 2026-06-01
Otrs MEDIUM 5.7
CVE-2026-48210

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default …

Mitigation only
Fix from $1,600 2026-05-31
Unclassified HIGH 8.8
CVE-2026-7465

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to…

Mitigation only
Fix from $1,950 2026-05-30
Unclassified CRITICAL 9.9
CVE-2026-47744

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.9
CVE-2026-45632

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. …

Mitigation only
Fix from $2,300 2026-05-29
Unclassified CRITICAL 9.3
CVE-2026-45043

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoi…

Mitigation only
Fix from $2,300 2026-05-29
Chrome HIGH 8.8
CVE-2026-9999

Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sa…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Chrome CRITICAL 9.6
CVE-2026-9918

Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a…

Fix: 148.0.7778.216+
Fix from $2,300 2026-05-28
Chrome HIGH 8.3
CVE-2026-9892

Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer p…

Fix: 148.0.7778.216+
Fix from $1,950 2026-05-28
Unclassified CRITICAL 9.8
CVE-2026-8809

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and inclu…

Mitigation only
Fix from $2,300 2026-05-28
E Business Suite HIGH 8.8
CVE-2026-46837

Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12…

Fix: after 12.2.15
Fix from $1,950 2026-05-28
Universal Work Queue CRITICAL 9.9
CVE-2026-46824

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported …

Fix: after 12.2.15
Fix from $2,300 2026-05-28
E Business Suite HIGH 8.8
CVE-2026-46827

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 1…

Fix: after 12.2.15
Fix from $1,950 2026-05-28
E Business Suite CRITICAL 9.8
CVE-2026-46817 KEVEPSS 13%

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.…

Fix: after 12.2.15
Fix from $2,300 2026-05-28
Local Path Provisioner HIGH 8.7
CVE-2026-44543

Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with perm…

Fix: 0.0.36+
Fix from $1,950 2026-05-28
Unclassified CRITICAL 9.3
CVE-2026-8980

The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the pa…

Mitigation only
Fix from $2,300 2026-05-28
Unclassified HIGH 8.8
CVE-2026-6226

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. T…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 8.5
CVE-2026-9789

A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the P…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 8.8
CVE-2026-45716

Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin mi…

Mitigation only
Fix from $1,950 2026-05-27
Unclassified HIGH 8.8
CVE-2026-8787

The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This i…

Mitigation only
Fix from $1,950 2026-05-27