Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified MEDIUM 6.4
CVE-2026-18702

An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affe…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.8
CVE-2026-15426

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization by…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.7
CVE-2026-73218

Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Do…

No fix yet
Fix from $4,900 2026-08-11
App Installer HIGH 7.8
CVE-2026-68821

Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.

Fix: 1.30.80+
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-20890

Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Process may allow an escalation o…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72534

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72537

A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-18950

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The sy…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72886

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72863

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au…

No fix yet
Fix from $5,750 2026-08-10
Unclassified MEDIUM 6.7
CVE-2026-16742

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user

No fix yet
Fix from $4,000 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-40920

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe…

No fix yet
Fix from $5,750 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-16298

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset th…

No fix yet
Fix from $5,750 2026-08-10
Unclassified HIGH 7.2
CVE-2026-14237

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-s…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.8
CVE-2026-19381

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library N…

No fix yet
Fix from $4,900 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-14526

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is du…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.9
CVE-2026-64637

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for th…

No fix yet
Fix from $2,300 2026-08-07
Unclassified HIGH 8.8
CVE-2026-15215

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscription…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.8
CVE-2026-19189

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows…

No fix yet
Fix from $1,950 2026-08-07
Unclassified CRITICAL 9.9
CVE-2026-48086

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN pr…

No fix yet
Fix from $2,300 2026-08-06
Api Control Plane CRITICAL 9.8
CVE-2026-1728

Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitati…

Fix: 4.0.0.384 / 4.1.0.248+
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19005

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file src/modules/agent-to-agent/cre…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19007

A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/a…

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.9
CVE-2026-9193

An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticate…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 8.1
CVE-2026-7327

An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 all…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-7329

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-8709

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows …

No fix yet
Fix from $2,300 2026-08-05
Build Of Keycloak MEDIUM 5.4
CVE-2026-16071

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when…

Fix: 26.4.14 / 26.6.5+
Fix from $1,600 2026-08-05
Unclassified HIGH 8.8
CVE-2026-18322

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to …

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.4
CVE-2026-64634

A vulnerability allowing local privilege escalation to the Reporter service context.

No fix yet
Fix from $1,950 2026-08-04