Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
MEDIUM 6.4 CVE-2026-18702 An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affe… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-15426 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization by… No fix yet Fix from $4,9002026-08-11 HIGH 7.7 CVE-2026-73218 Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Do… No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-68821 Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. App Installer 1.30.80+ Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-20890 Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Process may allow an escalation o… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-72534 A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-72537 A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-18950 A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The sy… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.9 CVE-2026-72886 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/… No fix yet Fix from $5,7502026-08-10 CRITICAL 9.9 CVE-2026-72863 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) au… No fix yet Fix from $5,7502026-08-10 MEDIUM 6.7 CVE-2026-16742 systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user No fix yet Fix from $4,0002026-08-10 CRITICAL 9.8 CVE-2026-40920 Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe… Ranger No fix yet Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-16298 The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset th… No fix yet Fix from $5,7502026-08-10 HIGH 7.2 CVE-2026-14237 The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-s… No fix yet Fix from $4,9002026-08-10 HIGH 7.8 CVE-2026-19381 A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library N… No fix yet Fix from $4,9002026-08-10 CRITICAL 9.8 CVE-2026-14526 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is du… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.9 CVE-2026-64637 Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for th… No fix yet Fix from $2,3002026-08-07 HIGH 8.8 CVE-2026-15215 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscription… No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-19189 A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows… No fix yet Fix from $1,9502026-08-07 CRITICAL 9.9 CVE-2026-48086 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN pr… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-1728 Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitati… Api Control Plane 4.0.0.384 / 4.1.0.248+ Fix from $2,3002026-08-06 MEDIUM 6.3 CVE-2026-19005 A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file src/modules/agent-to-agent/cre… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19007 A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/a… No fix yet Fix from $1,6002026-08-06 CRITICAL 9.9 CVE-2026-9193 An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticate… No fix yet Fix from $2,3002026-08-05 HIGH 8.1 CVE-2026-7327 An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 all… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.9 CVE-2026-7329 An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.9 CVE-2026-8709 An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows … No fix yet Fix from $2,3002026-08-05 MEDIUM 5.4 CVE-2026-16071 A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-18322 The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to … No fix yet Fix from $1,9502026-08-05 HIGH 8.4 CVE-2026-64634 A vulnerability allowing local privilege escalation to the Reporter service context. No fix yet Fix from $1,9502026-08-04