Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
MEDIUM 5.1 CVE-2026-15380 A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory c… No fix yet Fix from $1,6002026-07-17 MEDIUM 5.1 CVE-2026-15379 The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the… No fix yet Fix from $1,6002026-07-17 CRITICAL 9.8 CVE-2026-9810 The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator … Mitigation only Fix from $2,3002026-07-17 HIGH 8.1 CVE-2026-11961 The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is … Mitigation only Fix from $1,9502026-07-17 CRITICAL 9.8 CVE-2026-15982 The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in al… Mitigation only Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-14956 The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper val… No fix yet Fix from $2,3002026-07-17 HIGH 8.1 CVE-2026-43978 wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged … No fix yet Fix from $1,9502026-07-16 MEDIUM 6.5 CVE-2026-36425 An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send… No fix yet Fix from $1,6002026-07-16 HIGH 8.5 CVE-2026-6423 A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authentication in an IPC channel. Mitigation only Fix from $1,9502026-07-16 HIGH 8.8 CVE-2026-15103 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitr… No fix yet Fix from $1,9502026-07-16 HIGH 8.8 CVE-2026-13741 The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,… Mitigation only Fix from $1,9502026-07-16 HIGH 8.8 CVE-2026-12525 The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing … No fix yet Fix from $1,9502026-07-16 HIGH 7.6 CVE-2026-53444 Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/… Mitigation only Fix from $1,9502026-07-15 MEDIUM 5.4 CVE-2026-62355 TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine … Mitigation only Fix from $1,6002026-07-15 HIGH 7.1 CVE-2026-53515 Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register… Better Auth\/sso 1.6.11+ Fix from $1,9502026-07-15 CRITICAL 9.8 CVE-2026-14960 Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including… Mitigation only Fix from $2,3002026-07-15 MEDIUM 6.2 CVE-2026-14961 Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sensitive IOCTL functionality. T… Mitigation only Fix from $1,6002026-07-15 HIGH 8.8 CVE-2026-57996 phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create … Mitigation only Fix from $1,9502026-07-15 MEDIUM 6.7 CVE-2026-49501 Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerabili… Powerscale Onefs 9.10.1.8 / 9.13.1.0+ Fix from $1,6002026-07-15 HIGH 7.8 CVE-2026-50391 Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-50343 Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 MEDIUM 5.5 CVE-2026-50295 Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally. Windows 11 24h2 10.0.26100.8875 / 10.0.26100.33158+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-49176 Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 8.5 CVE-2026-53565 Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This iss… Mitigation only Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-52533 An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file No fix yet Fix from $2,3002026-07-13 HIGH 8.8 CVE-2026-61463 Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without… Patch available Fix from $1,9502026-07-13 HIGH 8.1 CVE-2026-59245 In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resour… Apache Airflow Providers Fab 3.7.2+ Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-59260 OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon wi… Mitigation only Fix from $1,9502026-07-12 HIGH 8.8 CVE-2026-14262 The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation i… Mitigation only Fix from $1,9502026-07-11 HIGH 8.8 CVE-2026-13756 The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing au… Mitigation only Fix from $1,9502026-07-11