Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
MEDIUM 5.5 CVE-2026-73973 Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/log… Fix unknown Fix from $4,0002026-08-18 MEDIUM 5.5 CVE-2026-73974 linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses … Fix unknown Fix from $4,0002026-08-18 HIGH 8.7 CVE-2026-75924 A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secr… Fix unknown Fix from $4,9002026-08-18 HIGH 7.0 CVE-2026-75857 CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement r… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74965 Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderb… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74952 Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 154. Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74953 Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunde… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74955 Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderb… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74950 Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74939 Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox E… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thun… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74942 Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Fi… Fix unknown Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-74935 Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox E… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.3 CVE-2026-75845 ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool. SetServerSetti… Fix unknown Fix from $4,0002026-08-18 CRITICAL 9.9 CVE-2026-75851 ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command … Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.9 CVE-2026-75843 ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated … Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.1 CVE-2026-75837 Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admi… Fix unknown Fix from $5,7502026-08-18 HIGH 8.0 CVE-2026-45790 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/se… Fix unknown Fix from $4,9002026-08-17 HIGH 8.8 CVE-2026-75481 SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers ca… Fix unknown Fix from $4,9002026-08-17 HIGH 8.8 CVE-2026-70495 A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and g… Fix unknown Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-50774 An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role. Fix unknown Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-50770 An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request. Fix unknown Fix from $5,7502026-08-17 HIGH 7.2 CVE-2026-17533 The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators o… Fix unknown Fix from $4,9002026-08-16 CRITICAL 9.8 CVE-2026-18432 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnera… No fix yet Fix from $5,7502026-08-16 MEDIUM 6.3 CVE-2026-19928 A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/R… No fix yet Fix from $4,0002026-08-16 HIGH 7.5 CVE-2026-15142 The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to i… No fix yet Fix from $4,9002026-08-15 HIGH 8.8 CVE-2026-14279 The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request… No fix yet Fix from $4,9002026-08-15 HIGH 8.8 CVE-2026-15001 The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.7… No fix yet Fix from $4,9002026-08-15 HIGH 8.8 CVE-2026-15312 The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, … No fix yet Fix from $4,9002026-08-15 HIGH 7.8 CVE-2026-69414 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;Shield… Malware Protection Engine No fix yet Fix from $4,9002026-08-14