Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.6
CVE-2026-26010
OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-b…
Openmetadata
1.11.8+
HIGH 7.6
CVE-2025-64487
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document…
Outline
1.1.0+
HIGH 7.8
CVE-2026-21533 KEV
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
CRITICAL 9.8
CVE-2025-15027
The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the …
Mitigation only
HIGH 8.8
CVE-2025-15100
The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the …
Mitigation only
CRITICAL 9.1
CVE-2026-25643
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.4, a critical Remote Command Execution (…
Frigate
0.16.4+
HIGH 7.8
CVE-2025-69875
A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and …
Total Security
Mitigation only
HIGH 7.8
CVE-2025-66374
CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administ…
Endpoint Privilege Manager
after 25.10.0
CRITICAL 9.8
CVE-2025-15030
The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to re…
Mitigation only
MEDIUM 5.8
CVE-2025-6723
Chef InSpec versions up to 5.23 and before 7.0.107 creates named pipes with overly permissive default Windows access controls. A local attacker may i…
Mitigation only
HIGH 8.4
CVE-2025-13176
Planting a custom configuration file
in
ESET Inspect Connector allow load a malicious DLL.
Mitigation only
HIGH 8.8
CVE-2026-23896
immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by …
Immich
2.5.0+
HIGH 8.1
CVE-2025-14975
The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests…
Mitigation only
HIGH 7.0
CVE-2025-13917
WSS Agent, prior to 9.8.5, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to …
No fix yet
MEDIUM 6.7
CVE-2025-13918
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability,…
Mitigation only
CRITICAL 9.9
CVE-2026-22039
Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization bo…
Kyverno
1.15.3 / 1.16.3+
HIGH 8.4
CVE-2025-59094
A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sysdef.exe). Within this applic…
Mitigation only
HIGH 8.8
CVE-2025-66428
An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.
Mitigation only
CRITICAL 9.8
CVE-2026-0920
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Administrative User Creation in all versions up to, and including, 1.5.…
Mitigation only
MEDIUM 5.3
CVE-2026-23990
The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterprise distribution. Starting in…
Flux Operator
0.40.0+
HIGH 7.5
CVE-2026-21983
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7…
Vm Virtualbox
Mitigation only
MEDIUM 6.0
CVE-2026-21963
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7…
Vm Virtualbox
Mitigation only
HIGH 7.5
CVE-2026-21957
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7…
Vm Virtualbox
Mitigation only
CRITICAL 9.8
CVE-2025-14533
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This i…
Mitigation only
CRITICAL 9.8
CVE-2025-15403
The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'a…
Mitigation only
HIGH 7.1
CVE-2026-21223
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
Edge Chromium
144.0.3719.82+
MEDIUM 5.4
CVE-2026-1010
A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form…
On Prem Enterprise Server
Mitigation only
HIGH 7.3
CVE-2025-67246
A local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL handler. This dr…
Ludashi Driver
5.1025+
MEDIUM 6.5
CVE-2026-23477
Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1…
Rocket.chat
6.12.0+
CRITICAL 9.8
CVE-2026-22708
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, ce…
Cursor
2.3+