Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Artifactory HIGH 7.2
CVE-2026-66015

An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploit…

Fix: 7.146.34 / 7.161.15+
Fix from $1,950 2026-07-27
Unclassified MEDIUM 6.5
CVE-2026-66399

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-ma…

No fix yet
Fix from $1,600 2026-07-27
Unclassified CRITICAL 9.8
CVE-2026-12394

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to regi…

No fix yet
Fix from $2,300 2026-07-27
Unclassified HIGH 8.1
CVE-2026-13152

The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to th…

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 8.4
CVE-2026-12502

Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.1…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 5.5
CVE-2026-16743

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and pr…

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 8.5
CVE-2026-10610

Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.5
CVE-2026-7483

Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.5
CVE-2026-12497

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not …

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.5
CVE-2026-12981

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthentica…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.0
CVE-2026-12736

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::sa…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.3
CVE-2026-16764

A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of t…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.8
CVE-2026-38764

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.1
CVE-2026-34496

Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.9
CVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a…

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 8.8
CVE-2026-65897

Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write c…

Mitigation only
Fix from $1,950 2026-07-23
Unclassified HIGH 8.8
CVE-2026-15017

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to mi…

No fix yet
Fix from $1,950 2026-07-23
Platform Security For Java CRITICAL 9.9
CVE-2026-60369

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Platform Security For Java HIGH 8.0
CVE-2026-60371

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $1,950 2026-07-22
Platform Security For Java CRITICAL 9.8
CVE-2026-60372

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Platform Security For Java HIGH 8.8
CVE-2026-60373

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $1,950 2026-07-22
Platform Security For Java HIGH 8.8
CVE-2026-60439

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

Mitigation only
Fix from $1,950 2026-07-22
Platform Security For Java HIGH 8.8
CVE-2026-60455

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $1,950 2026-07-22
Platform Security For Java HIGH 8.8
CVE-2026-61246

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 7.8
CVE-2026-38765

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 7.8
CVE-2026-38766

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function

No fix yet
Fix from $1,950 2026-07-22
Platform Security For Java CRITICAL 10.0
CVE-2026-60366

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Platform Security For Java CRITICAL 9.8
CVE-2026-60367

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Unclassified HIGH 7.8
CVE-2026-16607

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalat…

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 7.5
CVE-2026-62145EPSS 8%

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privi…

No fix yet
Fix from $1,950 2026-07-22