Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
MEDIUM 6.5 CVE-2026-55843 Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through Normal… Snipe It 8.6.0+ Fix from $1,6002026-07-10 CRITICAL 9.1 CVE-2026-51119 An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components Mitigation only Fix from $2,3002026-07-10 MEDIUM 6.5 CVE-2026-40009 Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by re… Mitigation only Fix from $1,6002026-07-10 HIGH 7.1 CVE-2026-44787 Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered us… Discourse 2026.1.5 / 2026.4.2+ Fix from $1,9502026-07-09 MEDIUM 6.7 CVE-2026-0275 A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macO… Prisma Browser 149.10.3.53+ Fix from $1,6002026-07-09 HIGH 7.8 CVE-2026-0276 A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root … Cortex Xdr Broker Vm 31.0.58+ Fix from $1,9502026-07-09 HIGH 8.1 CVE-2026-54652 Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the… Patch available Fix from $1,9502026-07-08 MEDIUM 6.3 CVE-2026-14250 The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to t… Mitigation only Fix from $1,6002026-07-08 HIGH 7.5 CVE-2026-9842 The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This i… Mitigation only Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-14482 The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The vulnerability exists d… Mitigation only Fix from $1,9502026-07-08 HIGH 7.1 CVE-2026-58583 FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user a… Mitigation only Fix from $1,9502026-07-07 HIGH 8.5 CVE-2026-53645 FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged staff account to grant arbitr… Mitigation only Fix from $1,9502026-07-06 HIGH 7.3 CVE-2026-14719 A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file r… Mitigation only Fix from $1,9502026-07-05 HIGH 7.8 CVE-2026-46680 containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directiv… Containerd 1.7.32 / 2.0.9+ Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-13228 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in ve… Mitigation only Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-12224 The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, … Mitigation only Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-57995 phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to gr… Mitigation only Fix from $1,9502026-06-30 HIGH 7.8 CVE-2026-14124 Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level pr… Chrome 150.0.7871.47+ Fix from $1,9502026-06-30 CRITICAL 9.6 CVE-2026-14101 Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer … Chrome 150.0.7871.47+ Fix from $2,3002026-06-30 HIGH 7.8 CVE-2025-7406 Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privilege… Mantaray Nm 25R2-NM+ Fix from $1,9502026-06-30 CRITICAL 9.9 CVE-2026-58053 Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig … Mitigation only Fix from $2,3002026-06-28 HIGH 7.2 CVE-2026-58054 MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers th… Mitigation only Fix from $1,9502026-06-28 CRITICAL 9.8 CVE-2026-12415 The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account… Mitigation only Fix from $2,3002026-06-27 MEDIUM 5.5 CVE-2026-45256 When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation was permitted but did not ch… FreeBSD Mitigation only Fix from $1,6002026-06-26 HIGH 7.1 CVE-2026-52808 Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/… Patch available Fix from $1,9502026-06-24 HIGH 8.2 CVE-2026-56245 Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time RPC function that allows unau… Mitigation only Fix from $1,9502026-06-24 HIGH 8.3 CVE-2026-56225 Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers (get/put/delete/post). API keys create… Mitigation only Fix from $1,9502026-06-23 HIGH 8.8 CVE-2026-54099 A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a … Openshift Container Platform 4.22.1+ Fix from $1,9502026-06-22 HIGH 8.8 CVE-2026-8157 The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API … Mitigation only Fix from $1,9502026-06-22 HIGH 7.6 CVE-2026-56239 Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY DEFINER function, which perf… Mitigation only Fix from $1,9502026-06-21