Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Openmetadata HIGH 7.6
CVE-2026-26010

OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-b…

Fix: 1.11.8+
Fix from $1,950 2026-02-11
Outline HIGH 7.6
CVE-2025-64487

Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document…

Fix: 1.1.0+
Fix from $1,950 2026-02-11
Windows 10 1607 HIGH 7.8
CVE-2026-21533 KEV

Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,950 2026-02-10
Unclassified CRITICAL 9.8
CVE-2025-15027

The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the …

Mitigation only
Fix from $2,300 2026-02-08
Unclassified HIGH 8.8
CVE-2025-15100

The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the …

Mitigation only
Fix from $1,950 2026-02-08
Frigate CRITICAL 9.1
CVE-2026-25643

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (…

Fix: 0.16.4+
Fix from $2,300 2026-02-06
Total Security HIGH 7.8
CVE-2025-69875

A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and …

Mitigation only
Fix from $1,950 2026-02-03
Endpoint Privilege Manager HIGH 7.8
CVE-2025-66374

CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administ…

Fix: after 25.10.0
Fix from $1,950 2026-02-03
Unclassified CRITICAL 9.8
CVE-2025-15030

The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to re…

Mitigation only
Fix from $2,300 2026-02-02
Unclassified MEDIUM 5.8
CVE-2025-6723

Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may i…

Mitigation only
Fix from $1,600 2026-01-30
Unclassified HIGH 8.4
CVE-2025-13176

Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.

Mitigation only
Fix from $1,950 2026-01-30
Immich HIGH 8.8
CVE-2026-23896

immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by …

Fix: 2.5.0+
Fix from $1,950 2026-01-29
Unclassified HIGH 8.1
CVE-2025-14975

The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests…

Mitigation only
Fix from $1,950 2026-01-29
Unclassified HIGH 7.0
CVE-2025-13917

WSS Agent, prior to 9.8.5, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to …

No fix yet
Fix from $1,950 2026-01-28
Unclassified MEDIUM 6.7
CVE-2025-13918

Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability,…

Mitigation only
Fix from $1,600 2026-01-28
Kyverno CRITICAL 9.9
CVE-2026-22039

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization bo…

Fix: 1.15.3 / 1.16.3+
Fix from $2,300 2026-01-27
Unclassified HIGH 8.4
CVE-2025-59094

A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sysdef.exe). Within this applic…

Mitigation only
Fix from $1,950 2026-01-26
Unclassified HIGH 8.8
CVE-2025-66428

An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.

Mitigation only
Fix from $1,950 2026-01-22
Unclassified CRITICAL 9.8
CVE-2026-0920

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.…

Mitigation only
Fix from $2,300 2026-01-22
Flux Operator MEDIUM 5.3
CVE-2026-23990

The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterprise distribution. Starting in…

Fix: 0.40.0+
Fix from $1,600 2026-01-21
Vm Virtualbox HIGH 7.5
CVE-2026-21983

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7…

Mitigation only
Fix from $1,950 2026-01-20
Vm Virtualbox MEDIUM 6.0
CVE-2026-21963

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7…

Mitigation only
Fix from $1,600 2026-01-20
Vm Virtualbox HIGH 7.5
CVE-2026-21957

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7…

Mitigation only
Fix from $1,950 2026-01-20
Unclassified CRITICAL 9.8
CVE-2025-14533

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This i…

Mitigation only
Fix from $2,300 2026-01-20
Unclassified CRITICAL 9.8
CVE-2025-15403

The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'a…

Mitigation only
Fix from $2,300 2026-01-17
Edge Chromium HIGH 7.1
CVE-2026-21223

Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

Fix: 144.0.3719.82+
Fix from $1,950 2026-01-16
On Prem Enterprise Server MEDIUM 5.4
CVE-2026-1010

A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form…

Mitigation only
Fix from $1,600 2026-01-15
Ludashi Driver HIGH 7.3
CVE-2025-67246

A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handler. This dr…

Fix: 5.1025+
Fix from $1,950 2026-01-15
Rocket.chat MEDIUM 6.5
CVE-2026-23477

Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1…

Fix: 6.12.0+
Fix from $1,600 2026-01-14
Cursor CRITICAL 9.8
CVE-2026-22708

Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce…

Fix: 2.3+
Fix from $2,300 2026-01-14