Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.8 CVE-2025-69689 The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dialog processes user-supplied pa… Mitigation only Fix from $1,9502026-04-27 HIGH 8.8 CVE-2026-7106 The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is d… Mitigation only Fix from $1,9502026-04-27 HIGH 8.8 CVE-2026-41359 OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class… Openclaw 2026.3.28+ Fix from $1,9502026-04-23 MEDIUM 5.9 CVE-2026-3621 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing unde… Websphere Application Server 26.0.0.5+ Fix from $1,6002026-04-23 MEDIUM 6.2 CVE-2026-6386 In order to apply a particular protection key to an address range, the kernel must update the corresponding page table entries. The subroutine which… FreeBSD Mitigation only Fix from $1,6002026-04-22 HIGH 8.8 CVE-2026-6761 Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 1… Firefox 140.10.0 / 150.0+ Fix from $1,9502026-04-21 HIGH 8.8 CVE-2026-6769 Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140… Firefox 140.10.0 / 150.0+ Fix from $1,9502026-04-21 HIGH 8.8 CVE-2026-6750 Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thund… Firefox 115.35.0 / 140.10.0+ Fix from $1,9502026-04-21 HIGH 7.8 CVE-2026-31368 AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability. No fix yet Fix from $1,9502026-04-21 HIGH 8.8 CVE-2026-39386 Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticat… Neko 3.0.11 / 3.1.2+ Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-29647 In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CSRs even … Patch available Fix from $1,6002026-04-20 HIGH 8.8 CVE-2026-29648 In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcfg and senvcfg. As a result, l… Patch available Fix from $1,9502026-04-20 MEDIUM 6.7 CVE-2026-35154 Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20… Data Domain Operating System 7.13.1.70 / 8.3.1.30+ Fix from $1,6002026-04-20 CRITICAL 9.9 CVE-2026-30269 Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role vi… Doorman Mitigation only Fix from $2,3002026-04-20 CRITICAL 9.3 CVE-2026-40317 NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary … Novumos 0.24+ Fix from $2,3002026-04-18 CRITICAL 9.0 CVE-2026-40572 NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 use… Novumos 0.24+ Fix from $2,3002026-04-18 CRITICAL 9.1 CVE-2026-40484 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive… Patch available Fix from $2,3002026-04-18 MEDIUM 5.5 CVE-2025-70795 STProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to terminate proce… Patch available Fix from $1,6002026-04-17 HIGH 8.8 CVE-2026-40002 Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems f… Nubia In Nx809j Firmware Mitigation only Fix from $1,9502026-04-17 HIGH 7.3 CVE-2026-23772 Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A low privile… Mitigation only Fix from $1,9502026-04-16 CRITICAL 9.8 CVE-2026-4880 The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege … Mitigation only Fix from $2,3002026-04-16 HIGH 8.8 CVE-2026-34393 Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This is… Weblate 5.17+ Fix from $1,9502026-04-15 HIGH 8.8 CVE-2026-40291 Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in th… Chamilo Lms after 1.11.38 Fix from $1,9502026-04-14 MEDIUM 5.5 CVE-2026-32212 Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform… Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32181 Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally. Windows 10 21h2 10.0.19044.7184 / 10.0.19045.7184+ Fix from $1,6002026-04-14 HIGH 8.8 CVE-2026-38529 A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to… Krayin Crm No fix yet Fix from $1,9502026-04-14 HIGH 8.8 CVE-2026-5144 The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the g… Patch available Fix from $1,9502026-04-11 HIGH 7.1 CVE-2026-33706 Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify their own status field via the u… Chamilo Lms 1.11.38+ Fix from $1,9502026-04-10 HIGH 8.3 CVE-2026-35595 Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only… Vikunja 2.3.0+ Fix from $1,9502026-04-10 HIGH 7.8 CVE-2026-29923 The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabli… Mitigation only Fix from $1,9502026-04-09