Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified CRITICAL 9.8
CVE-2025-12981

The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation …

Mitigation only
Fix from $2,300 2026-02-27
Wireguard Portal HIGH 8.8
CVE-2026-27899

WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-ad…

Fix: 2.1.3+
Fix from $1,950 2026-02-26
Aria Operations HIGH 7.2
CVE-2026-22721

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leve…

Fix: 5.2.3 / 8.18.6+
Fix from $1,950 2026-02-25
Endpoint Privilege Manager HIGH 7.8
CVE-2026-2914

CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation d…

Fix: 25.11.0+
Fix from $1,950 2026-02-25
Api Gateway Deploy HIGH 7.8
CVE-2026-27208

bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and P…

Mitigation only
Fix from $1,950 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2777

Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbi…

Fix: 115.33.0 / 140.8.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2780

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14…

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Firefox CRITICAL 9.8
CVE-2026-2782

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14…

Fix: 140.8.0 / 148.0+
Fix from $2,300 2026-02-24
Serv U HIGH 7.2
CVE-2025-40538

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and ex…

Fix: 15.5.4+
Fix from $1,950 2026-02-24
Formwork HIGH 8.8
CVE-2026-27198

Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based …

Fix: 2.3.4+
Fix from $1,950 2026-02-21
Global Facilities Management Software CRITICAL 9.4
CVE-2026-26722

An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of th…

No fix yet
Fix from $2,300 2026-02-20
Print Shop Pro Webdesk CRITICAL 9.8
CVE-2026-26725

An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate privileges via the AccessID p…

Mitigation only
Fix from $2,300 2026-02-20
Worktime HIGH 7.8
CVE-2025-15561

An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A mal…

Fix: after 11.8.8
Fix from $1,950 2026-02-19
Unclassified CRITICAL 9.8
CVE-2026-1994

The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is du…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified HIGH 8.8
CVE-2026-0912

The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capa…

Mitigation only
Fix from $1,950 2026-02-19
Unclassified CRITICAL 9.8
CVE-2025-13851

The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2025-13563

The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_l…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified CRITICAL 9.8
CVE-2025-12882

The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin all…

Mitigation only
Fix from $2,300 2026-02-19
Unclassified HIGH 7.8
CVE-2026-23599

A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux. Successful exploitat…

Mitigation only
Fix from $1,950 2026-02-18
Unclassified HIGH 8.7
CVE-2025-67905

Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-…

Mitigation only
Fix from $1,950 2026-02-17
Ax6600 Firmware HIGH 8.8
CVE-2026-2563

A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of…

Fix: after 4.5.1.r4533
Fix from $1,950 2026-02-16
Ax6600 Firmware HIGH 8.8
CVE-2026-2562

A vulnerability was determined in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This impacts the function cast_streen of the file /jdcapi of the co…

Fix: after 4.5.1.r4533
Fix from $1,950 2026-02-16
Ax6600 Firmware HIGH 8.8
CVE-2026-2561

A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_uptime of the file /jdcapi of the…

Fix: after 4.5.1.r4533
Fix from $1,950 2026-02-16
Enet Smart Home CRITICAL 9.8
CVE-2026-26369

eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSO…

Mitigation only
Fix from $2,300 2026-02-15
Unclassified HIGH 8.8
CVE-2026-1750

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.…

Mitigation only
Fix from $1,950 2026-02-15
Unclassified CRITICAL 9.8
CVE-2025-8572

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient…

Mitigation only
Fix from $2,300 2026-02-14
Unclassified HIGH 8.1
CVE-2026-2144

The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to…

Mitigation only
Fix from $1,950 2026-02-14
Frankenphp HIGH 7.5
CVE-2026-24894

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctl…

Fix: 1.11.2+
Fix from $1,950 2026-02-12
macOS MEDIUM 6.0
CVE-2025-46310

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26. An atta…

Fix: 14.8.4 / 15.7.4+
Fix from $1,600 2026-02-11
Cipace HIGH 8.8
CVE-2024-50619

Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A…

Fix: 9.17+
Fix from $1,950 2026-02-11