Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2026-63700 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with l… Wyse Management Suite No fix yet Fix from $4,9002026-08-14 HIGH 7.8 CVE-2026-63701 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged a… Wyse Management Suite No fix yet Fix from $4,9002026-08-14 HIGH 8.1 CVE-2026-16772 In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting ful… No fix yet Fix from $4,9002026-08-14 HIGH 7.2 CVE-2026-72828 Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-grou… No fix yet Fix from $4,9002026-08-14 CRITICAL 9.8 CVE-2026-72829 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. … No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-72830 Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write schedu… No fix yet Fix from $5,7502026-08-14 HIGH 8.8 CVE-2026-72833 The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted o… No fix yet Fix from $4,9002026-08-14 HIGH 8.1 CVE-2026-18039 The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved accoun… No fix yet Fix from $4,9002026-08-14 CRITICAL 9.0 CVE-2026-73842 OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go ex… No fix yet Fix from $5,7502026-08-13 HIGH 8.6 CVE-2026-73664 FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administ… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-73305 Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking app… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-18101 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps. No fix yet Fix from $4,9002026-08-13 HIGH 8.9 CVE-2026-18193 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses. No fix yet Fix from $4,9002026-08-13 HIGH 8.4 CVE-2026-18249 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-72631 Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy … No fix yet Fix from $4,0002026-08-13 HIGH 8.8 CVE-2026-16722 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management. I No fix yet Fix from $4,9002026-08-13 HIGH 7.8 CVE-2026-18071 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management. I No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-24059 The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration … No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-13610 The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauth… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-49819 UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.9 CVE-2026-73269 A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, … No fix yet Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-17082 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied … I No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-18713 IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user … I after 7.6 Fix from $4,9002026-08-12 CRITICAL 9.9 CVE-2026-17276 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high… I after 7.6 Fix from $5,7502026-08-12 HIGH 8.1 CVE-2026-16904 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during mo… I after 7.6 Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-73293 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProj… No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-73284 RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an atta… No fix yet Fix from $4,9002026-08-12 HIGH 7.2 CVE-2026-68752 A Project Resource Manager may gain broader administrative privileges under specific conditions. No fix yet Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-18366 The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress a… No fix yet Fix from $5,7502026-08-12 HIGH 7.7 CVE-2026-73122 A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromise… No fix yet Fix from $4,9002026-08-12