Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.8 CVE-2026-42289 ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely … Mitigation only Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-42844 Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upl… Grav No fix yet Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-44224 Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applie… Wiki.js 2.5.313+ Fix from $1,9502026-05-12 CRITICAL 9.9 CVE-2026-33821 Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. Dynamics 365 Customer Insights Mitigation only Fix from $2,3002026-05-12 HIGH 8.2 CVE-2026-43886 Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface.validateScope() uses Array.so… Mitigation only Fix from $1,9502026-05-11 HIGH 8.8 CVE-2026-41489 Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and … Mitigation only Fix from $1,9502026-05-11 HIGH 8.8 CVE-2026-28995 A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26… Ipados 18.7.9 / 26.5+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-28976 An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root privileges. macOS 26.5+ Fix from $1,9502026-05-11 HIGH 7.8 CVE-2026-28919 A consistency issue was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A… macOS 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 HIGH 7.8 CVE-2026-28840 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.4. A… macOS 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 HIGH 8.1 CVE-2026-42609 Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with o… Grav after 1.8.0 Fix from $1,9502026-05-11 MEDIUM 6.7 CVE-2026-26946 Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege management vulnerability in … Elastic Cloud Storage 4.3.0.0+ Fix from $1,6002026-05-11 HIGH 8.3 CVE-2026-42562 Plainpad is a self hosted note taking app. Prior to version 1.1.1, Plainpad allows a low-privilege authenticated user to self-escalate to administrat… Patch available Fix from $1,9502026-05-09 HIGH 7.0 CVE-2026-41163 bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then … Mitigation only Fix from $1,9502026-05-09 MEDIUM 5.5 CVE-2026-42185 People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0, a user holding the Administr… Patch available Fix from $1,6002026-05-08 HIGH 7.8 CVE-2026-8069 PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that use… Nitrosense 3.00.3198 / 3.01.3056+ Fix from $1,9502026-05-08 HIGH 7.8 CVE-2026-7994 Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege … Chrome 148.0.7778.96+ Fix from $1,9502026-05-06 MEDIUM 6.3 CVE-2026-7977 Inappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a crafted H… Chrome 148.0.7778.96+ Fix from $1,6002026-05-06 MEDIUM 6.3 CVE-2026-7971 Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML pag… Chrome 148.0.7778.96+ Fix from $1,6002026-05-06 MEDIUM 5.2 CVE-2026-40001 There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which may allow local arbitrary co… Mitigation only Fix from $1,6002026-05-06 MEDIUM 5.0 CVE-2026-7778 An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an inst… Mitigation only Fix from $1,6002026-05-05 CRITICAL 9.8 CVE-2025-13618 The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not p… Mitigation only Fix from $2,3002026-05-05 HIGH 8.8 CVE-2026-24072 An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges … HTTP Server 2.4.67+ Fix from $1,9502026-05-04 HIGH 8.8 CVE-2026-7641 The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via th… Mitigation only Fix from $1,9502026-05-02 HIGH 7.8 CVE-2025-52347 An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 Build 1004 … Mitigation only Fix from $1,9502026-05-01 HIGH 7.8 CVE-2026-37525 AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision Do command. The on_supervisio… Automotive Grade Linux after 17.1.12 Fix from $1,9502026-05-01 HIGH 7.8 CVE-2026-6389 IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, inclu… Turbonomic Prometurbo Agent 8.18.0+ Fix from $1,9502026-04-30 HIGH 7.8 CVE-2026-30769 An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escalate privileges via sending cr… Tvicport Mitigation only Fix from $1,9502026-04-29 HIGH 8.8 CVE-2026-5141 Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research… Mitigation only Fix from $1,9502026-04-29 HIGH 8.8 CVE-2026-6741 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and … Mitigation only Fix from $1,9502026-04-27