Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Wyse Management Suite HIGH 7.8
CVE-2026-63700

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with l…

No fix yet
Fix from $4,900 2026-08-14
Wyse Management Suite HIGH 7.8
CVE-2026-63701

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged a…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.1
CVE-2026-16772

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting ful…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.2
CVE-2026-72828

Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-grou…

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72829

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. …

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72830

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write schedu…

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 8.8
CVE-2026-72833

The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted o…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.1
CVE-2026-18039

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved accoun…

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.0
CVE-2026-73842

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go ex…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.6
CVE-2026-73664

FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administ…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-73305

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking app…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-18101

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.9
CVE-2026-18193

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.4
CVE-2026-18249

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72631

Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy …

No fix yet
Fix from $4,000 2026-08-13
I HIGH 8.8
CVE-2026-16722

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.8
CVE-2026-18071

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management.

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-24059

The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration …

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.5
CVE-2026-13610

The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauth…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-49819

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.9
CVE-2026-73269

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, …

No fix yet
Fix from $5,750 2026-08-12
I HIGH 8.8
CVE-2026-17082

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied …

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-18713

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user …

Fix: after 7.6
Fix from $4,900 2026-08-12
I CRITICAL 9.9
CVE-2026-17276

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high…

Fix: after 7.6
Fix from $5,750 2026-08-12
I HIGH 8.1
CVE-2026-16904

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during mo…

Fix: after 7.6
Fix from $4,900 2026-08-12
Unclassified HIGH 8.8
CVE-2026-73293

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProj…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.8
CVE-2026-73284

RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an atta…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.2
CVE-2026-68752

A Project Resource Manager may gain broader administrative privileges under specific conditions.

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-18366

The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress a…

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 7.7
CVE-2026-73122

A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromise…

No fix yet
Fix from $4,900 2026-08-12