Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
CRITICAL 9.0 CVE-2026-10868 A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::… Patch available Fix from $2,3002026-06-04 HIGH 7.8 CVE-2026-49189 Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations. Connect M6e 5g Firmware Mitigation only Fix from $1,9502026-06-04 CRITICAL 9.8 CVE-2026-8206 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in al… Mitigation only Fix from $2,3002026-06-02 MEDIUM 6.8 CVE-2026-0086 In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to loca… Android Mitigation only Fix from $1,6002026-06-01 HIGH 7.8 CVE-2026-0089 In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This cou… Android Mitigation only Fix from $1,9502026-06-01 HIGH 7.8 CVE-2026-0091 In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local… Android Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.2 CVE-2026-0046 In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This c… Android Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.8 CVE-2026-0048 In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead… Android Mitigation only Fix from $1,6002026-06-01 MEDIUM 6.2 CVE-2026-0055 In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory du… Android Mitigation only Fix from $1,6002026-06-01 HIGH 7.8 CVE-2026-0009 In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no addi… Android Mitigation only Fix from $1,9502026-06-01 MEDIUM 6.3 CVE-2026-10217 A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.g… Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.7 CVE-2026-48210 An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default … Otrs Mitigation only Fix from $1,6002026-05-31 HIGH 8.8 CVE-2026-7465 The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to… Mitigation only Fix from $1,9502026-05-30 CRITICAL 9.9 CVE-2026-47744 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel… Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.9 CVE-2026-45632 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. … Mitigation only Fix from $2,3002026-05-29 CRITICAL 9.3 CVE-2026-45043 RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoi… Mitigation only Fix from $2,3002026-05-29 HIGH 8.8 CVE-2026-9999 Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sa… Chrome 148.0.7778.216+ Fix from $1,9502026-05-28 CRITICAL 9.6 CVE-2026-9918 Inappropriate implementation in Tint in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a… Chrome 148.0.7778.216+ Fix from $2,3002026-05-28 HIGH 8.3 CVE-2026-9892 Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer p… Chrome 148.0.7778.216+ Fix from $1,9502026-05-28 CRITICAL 9.8 CVE-2026-8809 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and inclu… Mitigation only Fix from $2,3002026-05-28 HIGH 8.8 CVE-2026-46837 Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12… E Business Suite after 12.2.15 Fix from $1,9502026-05-28 CRITICAL 9.9 CVE-2026-46824 Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported … Universal Work Queue after 12.2.15 Fix from $2,3002026-05-28 HIGH 8.8 CVE-2026-46827 Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 1… E Business Suite after 12.2.15 Fix from $1,9502026-05-28 CRITICAL 9.8 CVE-2026-46817 KEVEPSS 13% Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.… E Business Suite after 12.2.15 Fix from $2,3002026-05-28 HIGH 8.7 CVE-2026-44543 Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with perm… Local Path Provisioner 0.0.36+ Fix from $1,9502026-05-28 CRITICAL 9.3 CVE-2026-8980 The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the pa… Mitigation only Fix from $2,3002026-05-28 HIGH 8.8 CVE-2026-6226 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. T… Mitigation only Fix from $1,9502026-05-28 HIGH 8.5 CVE-2026-9789 A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the P… Mitigation only Fix from $1,9502026-05-28 HIGH 8.8 CVE-2026-45716 Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin mi… Mitigation only Fix from $1,9502026-05-27 HIGH 8.8 CVE-2026-8787 The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This i… Mitigation only Fix from $1,9502026-05-27