Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2025-43306 A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may b… macOS 14.8 / 15.7+ Fix from $1,9502026-05-26 MEDIUM 5.5 CVE-2026-9490 A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This … Care Center 4.00.3060+ Fix from $1,6002026-05-25 HIGH 8.5 CVE-2026-9489 NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom p… Mitigation only Fix from $1,9502026-05-25 HIGH 8.8 CVE-2026-6419 The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This… Mitigation only Fix from $1,9502026-05-23 HIGH 8.8 CVE-2026-6895 The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation … Mitigation only Fix from $1,9502026-05-23 HIGH 8.8 CVE-2026-6897 The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\… Mitigation only Fix from $1,9502026-05-23 HIGH 8.8 CVE-2026-6898 The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3… Mitigation only Fix from $1,9502026-05-23 HIGH 7.5 CVE-2026-23663 Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. Global Secure Access No fix yet Fix from $1,9502026-05-22 HIGH 8.1 CVE-2026-40172 authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ A… Mitigation only Fix from $1,9502026-05-22 HIGH 8.8 CVE-2026-9018 The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in… Mitigation only Fix from $1,9502026-05-22 CRITICAL 9.8 CVE-2026-5118 The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin a… Mitigation only Fix from $2,3002026-05-21 MEDIUM 6.5 CVE-2026-45254 In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" in… FreeBSD No fix yet Fix from $1,6002026-05-21 CRITICAL 9.8 CVE-2026-7284 The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all … Mitigation only Fix from $2,3002026-05-20 HIGH 8.8 CVE-2026-7467 The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the … Mitigation only Fix from $1,9502026-05-20 CRITICAL 9.8 CVE-2026-31070 The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an admin… Mitigation only Fix from $2,3002026-05-19 HIGH 8.8 CVE-2026-8970 Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140… Firefox 140.11 / 140.11.0+ Fix from $1,9502026-05-19 HIGH 8.8 CVE-2026-8972 Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $1,9502026-05-19 HIGH 8.8 CVE-2026-8957 Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thun… Firefox 140.11 / 140.11.0+ Fix from $1,9502026-05-19 HIGH 8.8 CVE-2026-8952 Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. Firefox 151.0.0+ Fix from $1,9502026-05-19 HIGH 8.8 CVE-2026-8955 Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird… Firefox 140.11 / 140.11.0+ Fix from $1,9502026-05-19 HIGH 7.8 CVE-2026-32323 Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escala… Mullvad Vpn 2026.2+ Fix from $1,9502026-05-19 HIGH 8.8 CVE-2026-41085 Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited a… Mitigation only Fix from $1,9502026-05-18 HIGH 8.8 CVE-2026-8719 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is du… Mitigation only Fix from $1,9502026-05-17 HIGH 7.2 CVE-2026-45395 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the tool update endpoint (POST /ap… Open Webui 0.9.5+ Fix from $1,9502026-05-15 HIGH 8.1 CVE-2026-45675 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP and OAuth authentication … Open Webui 0.9.0+ Fix from $1,9502026-05-15 HIGH 7.1 CVE-2026-46333 In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fu… Linux Kernel 3.17 / 4.5+ Fix from $1,9502026-05-15 HIGH 8.8 CVE-2026-6228 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to i… Mitigation only Fix from $1,9502026-05-15 MEDIUM 6.0 CVE-2025-62625 Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sensitive keys, potentially resul… Mitigation only Fix from $1,6002026-05-14 MEDIUM 6.5 CVE-2026-5193 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privilege escalation in all versions… Mitigation only Fix from $1,6002026-05-14 HIGH 7.8 CVE-2026-44470 The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the Cowo… Claude Desktop 1.3834.0+ Fix from $1,9502026-05-13