Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
CRITICAL 9.8 CVE-2025-12981 The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation … Mitigation only Fix from $2,3002026-02-27 HIGH 8.8 CVE-2026-27899 WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-ad… Wireguard Portal 2.1.3+ Fix from $1,9502026-02-26 HIGH 7.2 CVE-2026-22721 VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leve… Aria Operations 5.2.3 / 8.18.6+ Fix from $1,9502026-02-25 HIGH 7.8 CVE-2026-2914 CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation d… Endpoint Privilege Manager 25.11.0+ Fix from $1,9502026-02-25 HIGH 7.8 CVE-2026-27208 bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and P… Api Gateway Deploy Mitigation only Fix from $1,9502026-02-24 CRITICAL 9.8 CVE-2026-2777 Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbi… Firefox 115.33.0 / 140.8.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2780 Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14… Firefox 140.8.0 / 148.0+ Fix from $2,3002026-02-24 CRITICAL 9.8 CVE-2026-2782 Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 14… Firefox 140.8.0 / 148.0+ Fix from $2,3002026-02-24 HIGH 7.2 CVE-2025-40538 A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and ex… Serv U 15.5.4+ Fix from $1,9502026-02-24 HIGH 8.8 CVE-2026-27198 Formwork is a flat file-based Content Management System (CMS). In versions 2.0.0 through 2.3.3, the application fails to properly enforce role-based … Formwork 2.3.4+ Fix from $1,9502026-02-21 CRITICAL 9.4 CVE-2026-26722 An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of th… Global Facilities Management Software No fix yet Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-26725 An issue in edu Business Solutions Print Shop Pro WebDesk v.18.34 (fixed in 19.76) allows a remote attacker to escalate privileges via the AccessID p… Print Shop Pro Webdesk Mitigation only Fix from $2,3002026-02-20 HIGH 7.8 CVE-2025-15561 An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A mal… Worktime after 11.8.8 Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2026-1994 The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is du… Mitigation only Fix from $2,3002026-02-19 HIGH 8.8 CVE-2026-0912 The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capa… Mitigation only Fix from $1,9502026-02-19 CRITICAL 9.8 CVE-2025-13851 The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-13563 The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_l… Mitigation only Fix from $2,3002026-02-19 CRITICAL 9.8 CVE-2025-12882 The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin all… Mitigation only Fix from $2,3002026-02-19 HIGH 7.8 CVE-2026-23599 A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux. Successful exploitat… Mitigation only Fix from $1,9502026-02-18 HIGH 8.7 CVE-2025-67905 Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-… Mitigation only Fix from $1,9502026-02-17 HIGH 8.8 CVE-2026-2563 A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of… Ax6600 Firmware after 4.5.1.r4533 Fix from $1,9502026-02-16 HIGH 8.8 CVE-2026-2562 A vulnerability was determined in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This impacts the function cast_streen of the file /jdcapi of the co… Ax6600 Firmware after 4.5.1.r4533 Fix from $1,9502026-02-16 HIGH 8.8 CVE-2026-2561 A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_uptime of the file /jdcapi of the… Ax6600 Firmware after 4.5.1.r4533 Fix from $1,9502026-02-16 CRITICAL 9.8 CVE-2026-26369 eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSO… Enet Smart Home Mitigation only Fix from $2,3002026-02-15 HIGH 8.8 CVE-2026-1750 The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.… Mitigation only Fix from $1,9502026-02-15 CRITICAL 9.8 CVE-2025-8572 The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient… Mitigation only Fix from $2,3002026-02-14 HIGH 8.1 CVE-2026-2144 The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to… Mitigation only Fix from $1,9502026-02-14 HIGH 7.5 CVE-2026-24894 FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctl… Frankenphp 1.11.2+ Fix from $1,9502026-02-12 MEDIUM 6.0 CVE-2025-46310 This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26. An atta… macOS 14.8.4 / 15.7.4+ Fix from $1,6002026-02-11 HIGH 8.8 CVE-2024-50619 Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A… Cipace 9.17+ Fix from $1,9502026-02-11