Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Unclassified HIGH 8.5
CVE-2026-18759

The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.8
CVE-2026-18606

A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program …

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.2
CVE-2026-15430

Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged …

No fix yet
Fix from $1,600 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-16534

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions du…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 8.8
CVE-2026-67356

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSe…

No fix yet
Fix from $1,950 2026-08-02
Unclassified CRITICAL 9.8
CVE-2026-16256

The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated us…

No fix yet
Fix from $2,300 2026-08-02
Unclassified HIGH 8.8
CVE-2026-16635

The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_up…

Mitigation only
Fix from $1,950 2026-08-01
Unclassified HIGH 8.1
CVE-2026-15368

The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly c…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.8
CVE-2026-15414

The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to …

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-14333

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and witho…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 8.1
CVE-2026-12251

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its regist…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 6.6
CVE-2026-65835

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResour…

No fix yet
Fix from $1,600 2026-07-30
Websphere Application Server HIGH 8.8
CVE-2026-14980

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to per…

Fix: 26.0.0.9+
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-12687

The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registrat…

No fix yet
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17969

Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbo…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17956

Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandb…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17950

Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 7.5
CVE-2026-17952

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.4
CVE-2026-17877

Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege es…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 7.8
CVE-2026-17863

Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation v…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 7.8
CVE-2026-17864

Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalat…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17868

Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privilege escalation via a crafte…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 7.5
CVE-2026-17816

Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the render…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-17751

Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 7.1
CVE-2026-17744

Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbo…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Unclassified HIGH 8.8
CVE-2026-12144

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to …

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.8
CVE-2026-18107

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-15992

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing a…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-14328

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all version…

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-14545

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end accou…

No fix yet
Fix from $2,300 2026-07-28