Vulnerability index

Browse CVEs

2,995 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.2 CVE-2026-66015 An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploit… Artifactory 7.146.34 / 7.161.15+ Fix from $1,9502026-07-27 MEDIUM 6.5 CVE-2026-66399 phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-ma… No fix yet Fix from $1,6002026-07-27 CRITICAL 9.8 CVE-2026-12394 The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to regi… No fix yet Fix from $2,3002026-07-27 HIGH 8.1 CVE-2026-13152 The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to th… No fix yet Fix from $1,9502026-07-27 HIGH 8.4 CVE-2026-12502 Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.1… No fix yet Fix from $1,9502026-07-24 MEDIUM 5.5 CVE-2026-16743 A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and pr… No fix yet Fix from $1,6002026-07-24 HIGH 8.5 CVE-2026-10610 Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user. No fix yet Fix from $1,9502026-07-24 HIGH 8.5 CVE-2026-7483 Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user. No fix yet Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-12497 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not … No fix yet Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-12981 The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthentica… No fix yet Fix from $1,9502026-07-24 HIGH 8.0 CVE-2026-12736 The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::sa… No fix yet Fix from $1,9502026-07-24 MEDIUM 6.3 CVE-2026-16764 A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of t… No fix yet Fix from $1,6002026-07-23 HIGH 7.8 CVE-2026-38764 An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys No fix yet Fix from $1,9502026-07-23 HIGH 7.1 CVE-2026-34496 Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1. No fix yet Fix from $1,9502026-07-23 CRITICAL 9.9 CVE-2026-15630 A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a… No fix yet Fix from $2,3002026-07-23 HIGH 8.8 CVE-2026-65897 Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write c… Mitigation only Fix from $1,9502026-07-23 HIGH 8.8 CVE-2026-15017 The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to mi… No fix yet Fix from $1,9502026-07-23 CRITICAL 9.9 CVE-2026-60369 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 HIGH 8.0 CVE-2026-60371 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 CRITICAL 9.8 CVE-2026-60372 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 HIGH 8.8 CVE-2026-60373 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-60439 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java Mitigation only Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-60455 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-61246 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 HIGH 7.8 CVE-2026-38765 An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys No fix yet Fix from $1,9502026-07-22 HIGH 7.8 CVE-2026-38766 An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function No fix yet Fix from $1,9502026-07-22 CRITICAL 10.0 CVE-2026-60366 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 CRITICAL 9.8 CVE-2026-60367 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 HIGH 7.8 CVE-2026-16607 A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalat… No fix yet Fix from $1,9502026-07-22 HIGH 7.5 CVE-2026-62145EPSS 8% A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privi… No fix yet Fix from $1,9502026-07-22