Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 8.5 CVE-2026-18759 The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by… No fix yet Fix from $1,9502026-08-04 HIGH 7.8 CVE-2026-18606 A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program … No fix yet Fix from $1,9502026-08-03 MEDIUM 6.2 CVE-2026-15430 Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged … No fix yet Fix from $1,6002026-08-03 CRITICAL 9.1 CVE-2026-16534 The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions du… No fix yet Fix from $2,3002026-08-03 HIGH 8.8 CVE-2026-67356 ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSe… No fix yet Fix from $1,9502026-08-02 CRITICAL 9.8 CVE-2026-16256 The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated us… No fix yet Fix from $2,3002026-08-02 HIGH 8.8 CVE-2026-16635 The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_up… Mitigation only Fix from $1,9502026-08-01 HIGH 8.1 CVE-2026-15368 The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly c… No fix yet Fix from $1,9502026-08-01 HIGH 8.8 CVE-2026-15414 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to … No fix yet Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-14333 The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and witho… No fix yet Fix from $1,9502026-07-31 HIGH 8.1 CVE-2026-12251 The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its regist… No fix yet Fix from $1,9502026-07-31 MEDIUM 6.6 CVE-2026-65835 Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResour… No fix yet Fix from $1,6002026-07-30 HIGH 8.8 CVE-2026-14980 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to per… Websphere Application Server 26.0.0.9+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-12687 The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registrat… No fix yet Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-17969 Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbo… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-17956 Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandb… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-17950 Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-17952 Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension … Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.4 CVE-2026-17877 Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege es… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 7.8 CVE-2026-17863 Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation v… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 7.8 CVE-2026-17864 Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalat… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-17868 Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privilege escalation via a crafte… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-17816 Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the render… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-17751 Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 7.1 CVE-2026-17744 Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbo… Chrome 151.0.7922.72+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-12144 The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to … No fix yet Fix from $1,9502026-07-29 HIGH 7.8 CVE-2026-18107 A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an… No fix yet Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-15992 The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing a… No fix yet Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-14328 The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all version… No fix yet Fix from $1,9502026-07-28 CRITICAL 9.8 CVE-2026-14545 The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end accou… No fix yet Fix from $2,3002026-07-28