Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.8 CVE-2026-35607 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Filebrowser after 2.63.0 Fix from $1,9502026-04-07 HIGH 8.4 CVE-2026-5373 An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Impr… Runzero Platform 4.0.260202.0+ Fix from $1,9502026-04-07 MEDIUM 6.7 CVE-2026-33727 Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability … Pi Hole Mitigation only Fix from $1,6002026-04-06 HIGH 7.8 CVE-2023-7343 Hirschmann Industrial HiVision versions 05.0.00 through 08.3.01 prior to 08.3.02 contain an arbitrary code execution vulnerability triggered when an … Mitigation only Fix from $1,9502026-04-02 HIGH 8.2 CVE-2024-44250 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbitrary co… macOS 15.1+ Fix from $1,9502026-04-02 HIGH 8.8 CVE-2023-7342 HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authenticated users with operator or a… Mitigation only Fix from $1,9502026-04-02 CRITICAL 9.8 CVE-2026-34528 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to ver… Filebrowser 2.62.2+ Fix from $2,3002026-04-01 HIGH 7.0 CVE-2026-34397 Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3.9 and 3.0.0-alpha to before … Himmelblau 2.3.9 / 3.1.1+ Fix from $1,9502026-04-01 MEDIUM 5.3 CVE-2026-33074 Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-l… Discourse 2026.1.3 / 2026.2.2+ Fix from $1,6002026-03-31 MEDIUM 5.5 CVE-2026-34218 ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup def… Clearancekit 4.2.14+ Fix from $1,6002026-03-31 HIGH 7.2 CVE-2026-33906 Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The … Ella Core 1.7.0+ Fix from $1,9502026-03-27 HIGH 8.8 CVE-2026-2931 The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to th… Mitigation only Fix from $1,9502026-03-26 HIGH 7.8 CVE-2026-30892 crun is an open source OCI Container Runtime fully written in C. In versions 1.19 through 1.26, the `crun exec` option `-u` (`--user`) is incorrectl… Crun 1.27+ Fix from $1,9502026-03-26 HIGH 7.0 CVE-2026-4824 A vulnerability has been found in Enter Software Iperius Backup up to 8.7.3. Affected by this issue is some unknown functionality of the component Ba… Mitigation only Fix from $1,9502026-03-25 CRITICAL 9.8 CVE-2025-70888 An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component Osslsigncode after 2.10 Fix from $2,3002026-03-25 HIGH 8.8 CVE-2025-70887 An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components Signify 0.9.2+ Fix from $1,9502026-03-25 MEDIUM 6.2 CVE-2026-28889 A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root. Xcode 26.4+ Fix from $1,6002026-03-25 HIGH 8.8 CVE-2026-33509 pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97, the set_config_value() API e… Pyload Ng 0.5.0b3.dev97+ Fix from $1,9502026-03-24 CRITICAL 9.6 CVE-2026-33334 Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron w… Vikunja 2.2.2+ Fix from $2,3002026-03-24 MEDIUM 5.5 CVE-2026-29111 systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. … Systemd 257.11 / 258.5+ Fix from $1,6002026-03-23 HIGH 8.8 CVE-2026-4314 The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3… Mitigation only Fix from $1,9502026-03-22 HIGH 8.1 CVE-2026-3629 The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. Th… Mitigation only Fix from $1,9502026-03-21 MEDIUM 6.5 CVE-2026-2375 The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, an… Mitigation only Fix from $1,6002026-03-21 HIGH 8.1 CVE-2026-31836 Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with … Checkmate after 3.5.1 Fix from $1,9502026-03-20 MEDIUM 5.5 CVE-2026-30888 Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a moderator to edit site policy do… Discourse 2026.1.2 / 2026.2.1+ Fix from $1,6002026-03-20 CRITICAL 9.8 CVE-2026-32760 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions … Filebrowser 2.62.0+ Fix from $2,3002026-03-20 HIGH 7.8 CVE-2026-30874 OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function al… Openwrt 24.10.6+ Fix from $1,9502026-03-19 HIGH 7.2 CVE-2026-25770 Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, … Wazuh 4.14.3+ Fix from $1,9502026-03-17 HIGH 7.2 CVE-2026-32106 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the REST API createUser endpoint uses string-b… Studiocms 0.4.3+ Fix from $1,9502026-03-11 MEDIUM 5.5 CVE-2026-2640 During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to … Mitigation only Fix from $1,6002026-03-11