Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2025-31272 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections a… macOS 15.4+ Fix from $1,9502026-06-11 CRITICAL 9.9 CVE-2026-50566 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 HIGH 8.5 CVE-2026-50570 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 CRITICAL 9.9 CVE-2026-50545 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-50563 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 CRITICAL 9.9 CVE-2026-50564 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $2,3002026-06-10 HIGH 8.7 CVE-2026-46617 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,9502026-06-10 MEDIUM 6.9 CVE-2026-46618 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior t… Patch available Fix from $1,6002026-06-10 CRITICAL 9.8 CVE-2025-6254 The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat… Mitigation only Fix from $2,3002026-06-10 HIGH 8.8 CVE-2026-11616 The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due t… Mitigation only Fix from $1,9502026-06-09 MEDIUM 5.5 CVE-2026-44119 Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges… HTTP Server 2.4.68+ Fix from $1,6002026-06-08 CRITICAL 9.4 CVE-2026-11423 A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in th… Mitigation only Fix from $2,3002026-06-05 HIGH 8.3 CVE-2025-5088 An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker t… Mitigation only Fix from $1,9502026-06-05 MEDIUM 6.3 CVE-2026-11308 Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious ex… Chrome 149.0.7827.53+ Fix from $1,6002026-06-05 HIGH 8.8 CVE-2026-11295 Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation … Chrome 149.0.7827.53+ Fix from $1,9502026-06-05 HIGH 7.5 CVE-2026-11296 Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer proce… Chrome 149.0.7827.53+ Fix from $1,9502026-06-05 MEDIUM 5.1 CVE-2026-11276 Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretionary… Chrome 149.0.7827.53+ Fix from $1,6002026-06-05 MEDIUM 6.1 CVE-2026-11229 Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physi… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 HIGH 8.8 CVE-2026-11108 Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via … Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 HIGH 7.8 CVE-2026-11103 Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege e… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 CRITICAL 9.0 CVE-2026-10868 A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::… Patch available Fix from $2,3002026-06-04 HIGH 7.8 CVE-2026-49189 Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations. Connect M6e 5g Firmware Mitigation only Fix from $1,9502026-06-04 CRITICAL 9.8 CVE-2026-8206 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in al… Mitigation only Fix from $2,3002026-06-02 MEDIUM 6.8 CVE-2026-0086 In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to loca… Android Mitigation only Fix from $1,6002026-06-01 HIGH 7.8 CVE-2026-0089 In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This cou… Android Mitigation only Fix from $1,9502026-06-01 HIGH 7.8 CVE-2026-0091 In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local… Android Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.2 CVE-2026-0046 In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This c… Android Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.8 CVE-2026-0048 In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead… Android Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.2 CVE-2026-0055 In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory du… Android Mitigation only Fix from $1,6002026-06-01 HIGH 7.8 CVE-2026-0009 In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no addi… Android Mitigation only Fix from $1,9502026-06-01