Vulnerability index

Browse CVEs

3,005 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.6 CVE-2026-26010 OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-b… Openmetadata 1.11.8+ Fix from $1,9502026-02-11 HIGH 7.6 CVE-2025-64487 Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document… Outline 1.1.0+ Fix from $1,9502026-02-11 HIGH 7.8 CVE-2026-21533 KEV Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,9502026-02-10 CRITICAL 9.8 CVE-2025-15027 The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the … Mitigation only Fix from $2,3002026-02-08 HIGH 8.8 CVE-2025-15100 The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the … Mitigation only Fix from $1,9502026-02-08 CRITICAL 9.1 CVE-2026-25643 Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (… Frigate 0.16.4+ Fix from $2,3002026-02-06 HIGH 7.8 CVE-2025-69875 A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and … Total Security Mitigation only Fix from $1,9502026-02-03 HIGH 7.8 CVE-2025-66374 CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administ… Endpoint Privilege Manager after 25.10.0 Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2025-15030 The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to re… Mitigation only Fix from $2,3002026-02-02 MEDIUM 5.8 CVE-2025-6723 Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may i… Mitigation only Fix from $1,6002026-01-30 HIGH 8.4 CVE-2025-13176 Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL. Mitigation only Fix from $1,9502026-01-30 HIGH 8.8 CVE-2026-23896 immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by … Immich 2.5.0+ Fix from $1,9502026-01-29 HIGH 8.1 CVE-2025-14975 The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests… Mitigation only Fix from $1,9502026-01-29 HIGH 7.0 CVE-2025-13917 WSS Agent, prior to 9.8.5, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to … No fix yet Fix from $1,9502026-01-28 MEDIUM 6.7 CVE-2025-13918 Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability,… Mitigation only Fix from $1,6002026-01-28 CRITICAL 9.9 CVE-2026-22039 Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization bo… Kyverno 1.15.3 / 1.16.3+ Fix from $2,3002026-01-27 HIGH 8.4 CVE-2025-59094 A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sysdef.exe). Within this applic… Mitigation only Fix from $1,9502026-01-26 HIGH 8.8 CVE-2025-66428 An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation. Mitigation only Fix from $1,9502026-01-22 CRITICAL 9.8 CVE-2026-0920 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.… Mitigation only Fix from $2,3002026-01-22 MEDIUM 5.3 CVE-2026-23990 The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterprise distribution. Starting in… Flux Operator 0.40.0+ Fix from $1,6002026-01-21 HIGH 7.5 CVE-2026-21983 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7… Vm Virtualbox Mitigation only Fix from $1,9502026-01-20 MEDIUM 6.0 CVE-2026-21963 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7… Vm Virtualbox Mitigation only Fix from $1,6002026-01-20 HIGH 7.5 CVE-2026-21957 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7… Vm Virtualbox Mitigation only Fix from $1,9502026-01-20 CRITICAL 9.8 CVE-2025-14533 The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This i… Mitigation only Fix from $2,3002026-01-20 CRITICAL 9.8 CVE-2025-15403 The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'a… Mitigation only Fix from $2,3002026-01-17 HIGH 7.1 CVE-2026-21223 Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. Edge Chromium 144.0.3719.82+ Fix from $1,9502026-01-16 MEDIUM 5.4 CVE-2026-1010 A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form… On Prem Enterprise Server Mitigation only Fix from $1,6002026-01-15 HIGH 7.3 CVE-2025-67246 A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handler. This dr… Ludashi Driver 5.1025+ Fix from $1,9502026-01-15 MEDIUM 6.5 CVE-2026-23477 Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1… Rocket.chat 6.12.0+ Fix from $1,6002026-01-14 CRITICAL 9.8 CVE-2026-22708 Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce… Cursor 2.3+ Fix from $2,3002026-01-14