Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.1
CVE-2026-15380
A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory c…
No fix yet
MEDIUM 5.1
CVE-2026-15379
The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the…
No fix yet
CRITICAL 9.8
CVE-2026-9810
The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator …
Mitigation only
HIGH 8.1
CVE-2026-11961
The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is …
Mitigation only
CRITICAL 9.8
CVE-2026-15982
The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in al…
Mitigation only
CRITICAL 9.8
CVE-2026-14956
The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper val…
No fix yet
HIGH 8.1
CVE-2026-43978
wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged …
No fix yet
MEDIUM 6.5
CVE-2026-36425
An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send…
No fix yet
HIGH 8.5
CVE-2026-6423
A local privilege escalation vulnerability in ESET Inspect Connector.
The vulnerability was caused by improper authentication in an IPC channel.
Mitigation only
HIGH 8.8
CVE-2026-15103
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitr…
No fix yet
HIGH 8.8
CVE-2026-13741
The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,…
Mitigation only
HIGH 8.8
CVE-2026-12525
The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing …
No fix yet
HIGH 7.6
CVE-2026-53444
Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/…
Mitigation only
MEDIUM 5.4
CVE-2026-62355
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine …
Mitigation only
HIGH 7.1
CVE-2026-53515
Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register…
Better Auth\/sso
1.6.11+
CRITICAL 9.8
CVE-2026-14960
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including…
Mitigation only
MEDIUM 6.2
CVE-2026-14961
Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sensitive IOCTL functionality. T…
Mitigation only
HIGH 8.8
CVE-2026-57996
phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create …
Mitigation only
MEDIUM 6.7
CVE-2026-49501
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerabili…
Powerscale Onefs
9.10.1.8 / 9.13.1.0+
HIGH 7.8
CVE-2026-50391
Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-50343
Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
MEDIUM 5.5
CVE-2026-50295
Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.
Windows 11 24h2
10.0.26100.8875 / 10.0.26100.33158+
HIGH 7.8
CVE-2026-49176
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 8.5
CVE-2026-53565
Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows.
This iss…
Mitigation only
CRITICAL 9.8
CVE-2026-52533
An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file
No fix yet
HIGH 8.8
CVE-2026-61463
Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without…
Patch available
HIGH 8.1
CVE-2026-59245
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resour…
Apache Airflow Providers Fab
3.7.2+
HIGH 8.8
CVE-2026-59260
OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon wi…
Mitigation only
HIGH 8.8
CVE-2026-14262
The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation i…
Mitigation only
HIGH 8.8
CVE-2026-13756
The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing au…
Mitigation only