Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified HIGH 8.8
CVE-2026-42289

ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely …

Mitigation only
Fix from $1,950 2026-05-12
Grav HIGH 8.8
CVE-2026-42844

Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upl…

No fix yet
Fix from $1,950 2026-05-12
Wiki.js HIGH 8.8
CVE-2026-44224

Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applie…

Fix: 2.5.313+
Fix from $1,950 2026-05-12
Dynamics 365 Customer Insights CRITICAL 9.9
CVE-2026-33821

Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-05-12
Unclassified HIGH 8.2
CVE-2026-43886

Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface.validateScope() uses Array.so…

Mitigation only
Fix from $1,950 2026-05-11
Unclassified HIGH 8.8
CVE-2026-41489

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and …

Mitigation only
Fix from $1,950 2026-05-11
Ipados HIGH 8.8
CVE-2026-28995

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26…

Fix: 18.7.9 / 26.5+
Fix from $1,950 2026-05-11
macOS HIGH 7.5
CVE-2026-28976

An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root privileges.

Fix: 26.5+
Fix from $1,950 2026-05-11
macOS HIGH 7.8
CVE-2026-28919

A consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
macOS HIGH 7.8
CVE-2026-28840

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.4. A…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Grav HIGH 8.1
CVE-2026-42609

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with o…

Fix: after 1.8.0
Fix from $1,950 2026-05-11
Elastic Cloud Storage MEDIUM 6.7
CVE-2026-26946

Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege management vulnerability in …

Fix: 4.3.0.0+
Fix from $1,600 2026-05-11
Unclassified HIGH 8.3
CVE-2026-42562

Plainpad is a self hosted note taking app. Prior to version 1.1.1, Plainpad allows a low-privilege authenticated user to self-escalate to administrat…

Patch available
Fix from $1,950 2026-05-09
Unclassified HIGH 7.0
CVE-2026-41163

bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then …

Mitigation only
Fix from $1,950 2026-05-09
Unclassified MEDIUM 5.5
CVE-2026-42185

People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0, a user holding the Administr…

Patch available
Fix from $1,600 2026-05-08
Nitrosense HIGH 7.8
CVE-2026-8069

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that use…

Fix: 3.00.3198 / 3.01.3056+
Fix from $1,950 2026-05-08
Chrome HIGH 7.8
CVE-2026-7994

Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege …

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Chrome MEDIUM 6.3
CVE-2026-7977

Inappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a crafted H…

Fix: 148.0.7778.96+
Fix from $1,600 2026-05-06
Chrome MEDIUM 6.3
CVE-2026-7971

Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML pag…

Fix: 148.0.7778.96+
Fix from $1,600 2026-05-06
Unclassified MEDIUM 5.2
CVE-2026-40001

There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which may allow local arbitrary co…

Mitigation only
Fix from $1,600 2026-05-06
Unclassified MEDIUM 5.0
CVE-2026-7778

An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an inst…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified CRITICAL 9.8
CVE-2025-13618

The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not p…

Mitigation only
Fix from $2,300 2026-05-05
HTTP Server HIGH 8.8
CVE-2026-24072

An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges …

Fix: 2.4.67+
Fix from $1,950 2026-05-04
Unclassified HIGH 8.8
CVE-2026-7641

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via th…

Mitigation only
Fix from $1,950 2026-05-02
Unclassified HIGH 7.8
CVE-2025-52347

An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 Build 1004 …

Mitigation only
Fix from $1,950 2026-05-01
Automotive Grade Linux HIGH 7.8
CVE-2026-37525

AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision Do command. The on_supervisio…

Fix: after 17.1.12
Fix from $1,950 2026-05-01
Turbonomic Prometurbo Agent HIGH 7.8
CVE-2026-6389

IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, inclu…

Fix: 8.18.0+
Fix from $1,950 2026-04-30
Tvicport HIGH 7.8
CVE-2026-30769

An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sending cr…

Mitigation only
Fix from $1,950 2026-04-29
Unclassified HIGH 8.8
CVE-2026-5141

Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research…

Mitigation only
Fix from $1,950 2026-04-29
Unclassified HIGH 8.8
CVE-2026-6741

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and …

Mitigation only
Fix from $1,950 2026-04-27