Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2026-24510
Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerability. A low privileged attacker …
Alienware Command Center
6.12.24.0+
CRITICAL 9.8
CVE-2026-31852
Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execut…
Jellyfin
Patch available
HIGH 7.8
CVE-2026-30902
Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local acc…
Rooms
6.4.15 / 6.5.13+
HIGH 8.8
CVE-2026-1993
The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. Th…
Mitigation only
CRITICAL 9.8
CVE-2026-2631
The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the …
Mitigation only
HIGH 7.2
CVE-2026-31834
Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under ce…
Umbraco Cms
16.5.1 / 17.2.2+
CRITICAL 9.4
CVE-2026-30960
rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical methods support and physics …
Mitigation only
HIGH 8.8
CVE-2025-15547
By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesyste…
FreeBSD
Mitigation only
HIGH 7.5
CVE-2025-15576
If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the…
FreeBSD
Mitigation only
HIGH 8.8
CVE-2025-8899
The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ…
Mitigation only
CRITICAL 9.8
CVE-2025-29165
An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component
Dir 1253 Firmware
Mitigation only
HIGH 8.8
CVE-2026-26416
An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users to escalate privileges across …
Cognix Platform
Mitigation only
MEDIUM 5.5
CVE-2026-28548
Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentia…
Emui
No fix yet
HIGH 7.8
CVE-2026-29127
The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured w…
Sfx2100 Firmware
No fix yet
MEDIUM 5.5
CVE-2026-29122
International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration …
Sfx2100 Firmware
No fix yet
HIGH 7.8
CVE-2026-29123
A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially pre…
Sfx2100 Firmware
No fix yet
HIGH 7.8
CVE-2026-29124
Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home…
Sfx2100 Firmware
No fix yet
HIGH 7.8
CVE-2026-29121
International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid bit set. This configuration g…
Sfx2100 Firmware
No fix yet
HIGH 8.3
CVE-2026-27802
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privile…
Vaultwarden
1.35.4+
HIGH 8.3
CVE-2026-27803
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has…
Vaultwarden
1.35.4+
MEDIUM 6.0
CVE-2026-20044
A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to p…
Mitigation only
HIGH 7.8
CVE-2025-63909
Incorrect access control in the component /opt/SRLtzm/bin/TapeDumper of Cohesity TranZman Migration Appliance Release 4.0 Build 14614 allows attacker…
Tranzman
No fix yet
CRITICAL 9.8
CVE-2026-1492EPSS 24%
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugi…
Mitigation only
HIGH 8.8
CVE-2026-1566
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege escalation via password reset in …
Mitigation only
HIGH 8.4
CVE-2026-21882
theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.2.0, improper privilege …
Patch available
HIGH 8.4
CVE-2026-0029
In __pkvm_init_vm of pkvm.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege…
Android
Patch available
HIGH 7.8
CVE-2026-0032
In multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local escalation…
Android
Patch available
HIGH 7.8
CVE-2026-0023
In createSessionInternal of PackageInstallerService.java, there is a possible way for an app to update its ownership due to a missing permission chec…
Android
Mitigation only
HIGH 7.8
CVE-2025-48645
In loadDescription of DeviceAdminInfo.java, there is a possible persistent package due to improper input validation. This could lead to local escalat…
Android
Mitigation only
HIGH 7.8
CVE-2025-48613
In VBMeta, there is a possible way to modify and resign VBMeta using a test key, assuming the original image was previously signed with the same key.…
Android
Mitigation only