Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
macOS HIGH 7.8
CVE-2025-43306

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may b…

Fix: 14.8 / 15.7+
Fix from $1,950 2026-05-26
Care Center MEDIUM 5.5
CVE-2026-9490

A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This …

Fix: 4.00.3060+
Fix from $1,600 2026-05-25
Unclassified HIGH 8.5
CVE-2026-9489

NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom p…

Mitigation only
Fix from $1,950 2026-05-25
Unclassified HIGH 8.8
CVE-2026-6419

The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This…

Mitigation only
Fix from $1,950 2026-05-23
Unclassified HIGH 8.8
CVE-2026-6895

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation …

Mitigation only
Fix from $1,950 2026-05-23
Unclassified HIGH 8.8
CVE-2026-6897

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\…

Mitigation only
Fix from $1,950 2026-05-23
Unclassified HIGH 8.8
CVE-2026-6898

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3…

Mitigation only
Fix from $1,950 2026-05-23
Global Secure Access HIGH 7.5
CVE-2026-23663

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-05-22
Unclassified HIGH 8.1
CVE-2026-40172

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ A…

Mitigation only
Fix from $1,950 2026-05-22
Unclassified HIGH 8.8
CVE-2026-9018

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in…

Mitigation only
Fix from $1,950 2026-05-22
Unclassified CRITICAL 9.8
CVE-2026-5118

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin a…

Mitigation only
Fix from $2,300 2026-05-21
FreeBSD MEDIUM 6.5
CVE-2026-45254

In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" in…

No fix yet
Fix from $1,600 2026-05-21
Unclassified CRITICAL 9.8
CVE-2026-7284

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all …

Mitigation only
Fix from $2,300 2026-05-20
Unclassified HIGH 8.8
CVE-2026-7467

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the …

Mitigation only
Fix from $1,950 2026-05-20
Unclassified CRITICAL 9.8
CVE-2026-31070

The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an admin…

Mitigation only
Fix from $2,300 2026-05-19
Firefox HIGH 8.8
CVE-2026-8970

Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140…

Fix: 140.11 / 140.11.0+
Fix from $1,950 2026-05-19
Firefox HIGH 8.8
CVE-2026-8972

Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $1,950 2026-05-19
Firefox HIGH 8.8
CVE-2026-8957

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thun…

Fix: 140.11 / 140.11.0+
Fix from $1,950 2026-05-19
Firefox HIGH 8.8
CVE-2026-8952

Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

Fix: 151.0.0+
Fix from $1,950 2026-05-19
Firefox HIGH 8.8
CVE-2026-8955

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird…

Fix: 140.11 / 140.11.0+
Fix from $1,950 2026-05-19
Mullvad Vpn HIGH 7.8
CVE-2026-32323

Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escala…

Fix: 2026.2+
Fix from $1,950 2026-05-19
Unclassified HIGH 8.8
CVE-2026-41085

Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited a…

Mitigation only
Fix from $1,950 2026-05-18
Unclassified HIGH 8.8
CVE-2026-8719

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is du…

Mitigation only
Fix from $1,950 2026-05-17
Open Webui HIGH 7.2
CVE-2026-45395

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the tool update endpoint (POST /ap…

Fix: 0.9.5+
Fix from $1,950 2026-05-15
Open Webui HIGH 8.1
CVE-2026-45675

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP and OAuth authentication …

Fix: 0.9.0+
Fix from $1,950 2026-05-15
Linux Kernel HIGH 7.1
CVE-2026-46333

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fu…

Fix: 3.17 / 4.5+
Fix from $1,950 2026-05-15
Unclassified HIGH 8.8
CVE-2026-6228

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to i…

Mitigation only
Fix from $1,950 2026-05-15
Unclassified MEDIUM 6.0
CVE-2025-62625

Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sensitive keys, potentially resul…

Mitigation only
Fix from $1,600 2026-05-14
Unclassified MEDIUM 6.5
CVE-2026-5193

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions…

Mitigation only
Fix from $1,600 2026-05-14
Claude Desktop HIGH 7.8
CVE-2026-44470

The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the Cowo…

Fix: 1.3834.0+
Fix from $1,950 2026-05-13