Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified HIGH 8.8
CVE-2025-69689

The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dialog processes user-supplied pa…

Mitigation only
Fix from $1,950 2026-04-27
Unclassified HIGH 8.8
CVE-2026-7106

The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is d…

Mitigation only
Fix from $1,950 2026-04-27
Openclaw HIGH 8.8
CVE-2026-41359

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class…

Fix: 2026.3.28+
Fix from $1,950 2026-04-23
Websphere Application Server MEDIUM 5.9
CVE-2026-3621

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing unde…

Fix: 26.0.0.5+
Fix from $1,600 2026-04-23
FreeBSD MEDIUM 6.2
CVE-2026-6386

In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which…

Mitigation only
Fix from $1,600 2026-04-22
Firefox HIGH 8.8
CVE-2026-6761

Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 1…

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 8.8
CVE-2026-6769

Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140…

Fix: 140.10.0 / 150.0+
Fix from $1,950 2026-04-21
Firefox HIGH 8.8
CVE-2026-6750

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thund…

Fix: 115.35.0 / 140.10.0+
Fix from $1,950 2026-04-21
Unclassified HIGH 7.8
CVE-2026-31368

AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.

No fix yet
Fix from $1,950 2026-04-21
Neko HIGH 8.8
CVE-2026-39386

Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticat…

Fix: 3.0.11 / 3.1.2+
Fix from $1,950 2026-04-21
Unclassified MEDIUM 6.5
CVE-2026-29647

In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CSRs even …

Patch available
Fix from $1,600 2026-04-20
Unclassified HIGH 8.8
CVE-2026-29648

In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcfg and senvcfg. As a result, l…

Patch available
Fix from $1,950 2026-04-20
Data Domain Operating System MEDIUM 6.7
CVE-2026-35154

Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20…

Fix: 7.13.1.70 / 8.3.1.30+
Fix from $1,600 2026-04-20
Doorman CRITICAL 9.9
CVE-2026-30269

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role vi…

Mitigation only
Fix from $2,300 2026-04-20
Novumos CRITICAL 9.3
CVE-2026-40317

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary …

Fix: 0.24+
Fix from $2,300 2026-04-18
Novumos CRITICAL 9.0
CVE-2026-40572

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 use…

Fix: 0.24+
Fix from $2,300 2026-04-18
Unclassified CRITICAL 9.1
CVE-2026-40484

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive…

Patch available
Fix from $2,300 2026-04-18
Unclassified MEDIUM 5.5
CVE-2025-70795

STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate proce…

Patch available
Fix from $1,600 2026-04-17
Nubia In Nx809j Firmware HIGH 8.8
CVE-2026-40002

Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems f…

Mitigation only
Fix from $1,950 2026-04-17
Unclassified HIGH 7.3
CVE-2026-23772

Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A low privile…

Mitigation only
Fix from $1,950 2026-04-16
Unclassified CRITICAL 9.8
CVE-2026-4880

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege …

Mitigation only
Fix from $2,300 2026-04-16
Weblate HIGH 8.8
CVE-2026-34393

Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This is…

Fix: 5.17+
Fix from $1,950 2026-04-15
Chamilo Lms HIGH 8.8
CVE-2026-40291

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in th…

Fix: after 1.11.38
Fix from $1,950 2026-04-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-32212

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 21h2 MEDIUM 5.5
CVE-2026-32181

Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.

Fix: 10.0.19044.7184 / 10.0.19045.7184+
Fix from $1,600 2026-04-14
Krayin Crm HIGH 8.8
CVE-2026-38529

A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to…

No fix yet
Fix from $1,950 2026-04-14
Unclassified HIGH 8.8
CVE-2026-5144

The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the g…

Patch available
Fix from $1,950 2026-04-11
Chamilo Lms HIGH 7.1
CVE-2026-33706

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify their own status field via the u…

Fix: 1.11.38+
Fix from $1,950 2026-04-10
Vikunja HIGH 8.3
CVE-2026-35595

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only…

Fix: 2.3.0+
Fix from $1,950 2026-04-10
Unclassified HIGH 7.8
CVE-2026-29923

The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabli…

Mitigation only
Fix from $1,950 2026-04-09