CVE z tagiem privilege-escalation — 200 wyników. ← Wszystkie tagi

CVE-2015-0016 🔴 Łataj teraz KEV
appscloud

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Window…

CVE-2016-0099 🔴 Łataj teraz KEV
appscloud

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly …

7.8 CVSS
90.4% EPSS
CVE-2017-0213 🔴 Łataj teraz KEV
appscloud

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016…

7.3 CVSS
92.7% EPSS
CVE-2015-1701 🔴 Łataj teraz KEV
appscloud

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win…

7.8 CVSS
90.2% EPSS
CVE-2016-7255 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server…

7.8 CVSS
89.4% EPSS
CVE-2014-1812 🔴 Łataj teraz KEV
appscloud

The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of pass…

8.8 CVSS
83.1% EPSS
CVE-2014-4113 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Go…

7.8 CVSS
82.4% EPSS
CVE-2016-0040 🔴 Łataj teraz KEV
appscloud

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

7.8 CVSS
78.9% EPSS
CVE-2017-0101 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607;…

7.8 CVSS
67.2% EPSS
CVE-2011-2005 🔴 Łataj teraz KEV
appscloud

afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted…

7.8 CVSS
67.1% EPSS
CVE-2014-4123 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a differ…

8.8 CVSS
50.6% EPSS
CVE-2014-4077 🔴 Łataj teraz KEV
appscloud

Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandb…

7.8 CVSS
50.8% EPSS
CVE-2017-0210 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain…

8.8 CVSS
42.1% EPSS
CVE-2016-3309 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local use…

7.8 CVSS
46.3% EPSS
CVE-2015-2546 🔴 Łataj teraz KEV
appscloud

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local user…

8.2 CVSS
39.8% EPSS
CVE-2014-2817 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

8.8 CVSS
26.4% EPSS
CVE-2015-1769 🔴 Łataj teraz KEV
appscloud

Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which…

6.6 CVSS
31.8% EPSS
CVE-2017-0001 🔴 Łataj teraz KEV
appscloud

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all…

7.8 CVSS
25.4% EPSS
CVE-2017-0263 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local…

7.8 CVSS
18.5% EPSS
CVE-2026-48172 🔴 Łataj teraz KEV

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /v…

9.8 CVSS
8.0% EPSS
CVE-2015-2360 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wi…

8.8 CVSS
11.6% EPSS
CVE-2023-36424 🔴 Łataj teraz KEV
appscloud

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8 CVSS
10.7% EPSS
CVE-2017-0005 🔴 Łataj teraz KEV
appscloud

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all…

7.8 CVSS
8.0% EPSS
CVE-2016-0167 🔴 Łataj teraz KEV
appscloud

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to g…

7.8 CVSS
6.1% EPSS
CVE-2016-0165 🔴 Łataj teraz KEV
appscloud

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to g…

7.8 CVSS
6.0% EPSS
CVE-2015-6175 🔴 Łataj teraz KEV
appscloud

The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."

7.8 CVSS
2.8% EPSS
CVE-2024-50483 🔴 Łataj teraz

Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.

9.8 CVSS
54.0% EPSS
CVE-2023-3277 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows un…

9.8 CVSS
38.7% EPSS
CVE-2010-1225 🔴 Łataj teraz
appscloud

The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restric…

9.3 CVSS
38.9% EPSS
CVE-2024-50475 🔴 Łataj teraz

Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affects Signup Page: from n/a through <= 1.0.

9.8 CVSS
32.0% EPSS
CVE-2024-50476 🟠 Łataj w tym tygodniu

Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.

9.8 CVSS
24.7% EPSS
CVE-2024-50485 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issue affects Exam Matrix: from n/a through <= 1.5.

9.8 CVSS
21.9% EPSS
CVE-2023-2833 🟠 Łataj w tym tygodniu

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenti…

8.8 CVSS
26.8% EPSS
CVE-2023-3124 🟠 Łataj w tym tygodniu

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible…

8.8 CVSS
26.0% EPSS
CVE-2023-6246 🟠 Łataj w tym tygodniu

A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or …

CVE-2023-2916 🟡 Monitoruj

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-…

7.5 CVSS
29.5% EPSS
CVE-2022-4939 🟠 Łataj w tym tygodniu

THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that contro…

9.8 CVSS
7.3% EPSS
CVE-2023-5178 🟡 Monitoruj
os

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-a…

8.8 CVSS
9.3% EPSS
CVE-2023-35175 🟠 Łataj w tym tygodniu

Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.

9.8 CVSS
1.8% EPSS
CVE-2026-39907 🔴 Łataj teraz

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allo…

10.0 CVSS
0.6% EPSS
CVE-2024-10035 🟠 Łataj w tym tygodniu

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Comma…

9.8 CVSS
1.3% EPSS
CVE-2026-39906 🔴 Łataj teraz

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a Win…

10.0 CVSS
0.2% EPSS
CVE-2024-2172 🟠 Łataj w tym tygodniu

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all version…

9.8 CVSS
1.1% EPSS
CVE-2026-47938 🟠 Łataj w tym tygodniu

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require…

10.0 CVSS
0.1% EPSS
CVE-2026-56142 🟠 Łataj w tym tygodniu

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible

9.9 CVSS
0.4% EPSS
CVE-2023-27971 🟠 Łataj w tym tygodniu

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.

9.8 CVSS
0.9% EPSS
CVE-2026-42368 🟠 Łataj w tym tygodniu

A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpag…

9.9 CVSS
0.4% EPSS
CVE-2026-49252 🟠 Łataj w tym tygodniu

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential priv…

9.9 CVSS
0.3% EPSS
CVE-2026-35031 🟠 Łataj w tym tygodniu

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, all…

9.9 CVSS
0.2% EPSS
CVE-2026-32922 🟠 Łataj w tym tygodniu

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scope…

9.9 CVSS
0.2% EPSS
CVE-2026-12415 🟠 Łataj w tym tygodniu

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is …

9.8 CVSS
0.7% EPSS
CVE-2026-26369 🔴 Łataj teraz

eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST r…

9.8 CVSS
0.6% EPSS
CVE-2021-4360 🔴 Łataj teraz

The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for atta…

9.9 CVSS
0.1% EPSS
CVE-2026-11551 🟠 Łataj w tym tygodniu

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updati…

9.8 CVSS
0.6% EPSS
CVE-2026-33945 🟠 Łataj w tym tygodniu

Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0,…

9.9 CVSS
0.1% EPSS
CVE-2026-7813 🟠 Łataj w tym tygodniu

Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. Multiple endpoints fetched user-owned objects without filtering by the r…

9.9 CVSS
0.1% EPSS
CVE-2026-34571 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerab…

9.9 CVSS
0.1% EPSS
CVE-2026-44962 🟠 Łataj w tym tygodniu

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated,…

9.9 CVSS
0.1% EPSS
CVE-2024-37927 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in NooTheme Jobmonster noo-jobmonster allows Privilege Escalation.This issue affects Jobmonster: from n/a through <= 4.7.5.

9.8 CVSS
0.5% EPSS
CVE-2026-30269 🔴 Łataj teraz

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is accepted by the update…

9.9 CVSS
0.0% EPSS
CVE-2026-41329 🟠 Łataj w tym tygodniu

OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulation. Attackers can exploit improper conte…

9.9 CVSS
0.0% EPSS
CVE-2026-33579 🟠 Łataj w tym tygodniu

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without adm…

9.9 CVSS
0.0% EPSS
CVE-2025-69179 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.

9.8 CVSS
0.4% EPSS
CVE-2026-12417 🟠 Łataj w tym tygodniu

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_pa…

9.8 CVSS
0.4% EPSS
CVE-2026-4003 🟠 Łataj w tym tygodniu

The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due to a flawed authorization logic check in the usersp…

9.8 CVSS
0.4% EPSS
CVE-2026-39583 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.

9.8 CVSS
0.4% EPSS
CVE-2026-56028 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions.

9.8 CVSS
0.4% EPSS
CVE-2025-32491 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO – On-site SEO rankology-seo-all-in-one-seo-analytics allows Privilege Escalation.This issue affects Rankology SEO – On-site SEO: from n/a through <=…

9.8 CVSS
0.4% EPSS
CVE-2024-49322 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in CodePassenger Job Board Manager for WordPress jemployee allows Privilege Escalation.This issue affects Job Board Manager for WordPress: from n/a through <= 1.0.

9.8 CVSS
0.3% EPSS
CVE-2026-56030 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-56033 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-34901 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.

9.8 CVSS
0.3% EPSS
CVE-2024-49217 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in madiriaashish Adding drop down roles in registration user-drop-down-roles-in-registration allows Privilege Escalation.This issue affects Adding drop down roles in registrat…

9.8 CVSS
0.3% EPSS
CVE-2026-8181 🟠 Łataj w tym tygodniu

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value h…

9.8 CVSS
0.3% EPSS
CVE-2023-4404 🟠 Łataj w tym tygodniu

The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it pos…

9.8 CVSS
0.2% EPSS
CVE-2024-56000 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/a through < 5.4.0.

9.8 CVSS
0.2% EPSS
CVE-2026-6510 🟠 Łataj w tym tygodniu

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the …

9.8 CVSS
0.2% EPSS
CVE-2026-8809 🟠 Łataj w tym tygodniu

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_p…

9.8 CVSS
0.2% EPSS
CVE-2023-2987 🟠 Łataj w tym tygodniu

The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This m…

9.8 CVSS
0.2% EPSS
CVE-2026-4880 🟠 Łataj w tym tygodniu

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up t…

9.8 CVSS
0.1% EPSS
CVE-2025-67112 🟠 Łataj w tym tygodniu

Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote authenticated users to decrypt…

9.8 CVSS
0.1% EPSS
CVE-2026-24178 🟠 Łataj w tym tygodniu
os

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of thi…

9.8 CVSS
0.1% EPSS
CVE-2026-8206 🟠 Łataj w tym tygodniu

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbit…

9.8 CVSS
0.1% EPSS
CVE-2023-51484 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in wp-buy Login as User or Customer (User Switching) login-as-customer-or-user allows Privilege Escalation.This issue affects Login as User or Customer (User Switching): from …

9.8 CVSS
0.1% EPSS
CVE-2023-3374 🟠 Łataj w tym tygodniu

Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation.This issue affects Bookreen: before 3.0.0.

9.8 CVSS
0.1% EPSS
CVE-2021-47932 🟠 Łataj w tym tygodniu

WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send …

9.8 CVSS
0.1% EPSS
CVE-2026-7284 🟠 Łataj w tym tygodniu

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle…

9.8 CVSS
0.1% EPSS
CVE-2025-13618 🟠 Łataj w tym tygodniu

The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not properly restricting the roles that users can register with in the mento…

9.8 CVSS
0.1% EPSS
CVE-2026-27960 🟠 Łataj w tym tygodniu

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticate…

9.8 CVSS
0.1% EPSS
CVE-2026-30118 🟠 Łataj w tym tygodniu

scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers to force the backend…

9.8 CVSS
0.1% EPSS
CVE-2026-8732 🟠 Łataj w tym tygodniu

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being regis…

9.8 CVSS
0.1% EPSS
CVE-2026-4038 🟠 Łataj w tym tygodniu

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions u…

9.8 CVSS
0.1% EPSS
CVE-2026-24971 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8.

9.8 CVSS
0.1% EPSS
CVE-2026-24968 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30.

9.8 CVSS
0.1% EPSS
CVE-2026-27051 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0.

9.8 CVSS
0.1% EPSS
CVE-2026-32520 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through <= 1.0.4.

9.8 CVSS
0.1% EPSS
CVE-2026-2777 🟠 Łataj w tym tygodniu

Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

9.8 CVSS
0.1% EPSS
CVE-2026-2782 🟠 Łataj w tym tygodniu

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

9.8 CVSS
0.1% EPSS
CVE-2026-9094 🟠 Łataj w tym tygodniu

Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the t…

9.8 CVSS
0.1% EPSS
CVE-2026-32987 🟠 Łataj w tym tygodniu

OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to esc…

9.8 CVSS
0.0% EPSS
CVE-2026-42731 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.

9.8 CVSS
0.0% EPSS
CVE-2026-42758 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253.

9.8 CVSS
0.0% EPSS
CVE-2025-6254 🟠 Łataj w tym tygodniu

The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles tha…

9.8 CVSS
0.0% EPSS
CVE-2026-49060 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.

9.8 CVSS
0.0% EPSS
CVE-2016-20024 🟠 Łataj w tym tygodniu

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the Z…

9.8 CVSS
0.0% EPSS
CVE-2026-30793 🔴 Łataj teraz
os

Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This…

9.8 CVSS
0.0% EPSS
CVE-2026-5118 🟠 Łataj w tym tygodniu

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user …

9.8 CVSS
0.0% EPSS
CVE-2026-27542 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Captu…

9.8 CVSS
0.0% EPSS
CVE-2026-4717 🟠 Łataj w tym tygodniu

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

9.8 CVSS
0.0% EPSS
CVE-2026-2780 🟠 Łataj w tym tygodniu

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

9.8 CVSS
0.0% EPSS
CVE-2025-53209 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.

9.8 CVSS
0.0% EPSS
CVE-2026-48898 🟠 Łataj w tym tygodniu
apps

An improper access check allows privilege escalation through the com_users batch task.

9.8 CVSS
0.0% EPSS
CVE-2026-48899 🟠 Łataj w tym tygodniu
apps

An improper access check allows privilege escalation through the com_users batch task.

9.8 CVSS
0.0% EPSS
CVE-2026-42680 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.

9.8 CVSS
0.0% EPSS
CVE-2026-48879 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

9.8 CVSS
0.0% EPSS
CVE-2026-42235 🟠 Łataj w tym tygodniu

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user aut…

9.6 CVSS
0.1% EPSS
CVE-2026-39821 🟠 Łataj w tym tygodniu

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an erro…

9.6 CVSS
0.1% EPSS
CVE-2025-7743 🟠 Łataj w tym tygodniu

Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalation. This issue affects Omaspot: before 12.09.2025.

9.6 CVSS
0.0% EPSS
CVE-2026-40702 🟠 Łataj w tym tygodniu

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform un…

9.4 CVSS
0.4% EPSS
CVE-2025-4404 🟠 Łataj w tym tygodniu

A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the `krbCanonicalName` for the admin account by default, allowing users t…

9.1 CVSS
1.8% EPSS
CVE-2026-25192 🟠 Łataj w tym tygodniu

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP Web…

9.4 CVSS
0.2% EPSS
CVE-2026-22552 🟠 Łataj w tym tygodniu

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP Web…

9.4 CVSS
0.2% EPSS
CVE-2026-26288 🟠 Łataj w tym tygodniu

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP Web…

9.4 CVSS
0.2% EPSS
CVE-2026-26051 🟠 Łataj w tym tygodniu

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP Web…

9.4 CVSS
0.2% EPSS
CVE-2026-25150 🟠 Łataj w tym tygodniu

Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form fie…

9.3 CVSS
0.6% EPSS
CVE-2026-29796 🟠 Łataj w tym tygodniu

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP Web…

9.4 CVSS
0.1% EPSS
CVE-2026-33950 🔴 Łataj teraz

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a privilege escalation vulnerability by Admin Role Injection via /enableSecurity. An unauthenticated …

9.4 CVSS
0.1% EPSS
CVE-2026-40317 🔴 Łataj teraz

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers without validation, allow…

9.3 CVSS
0.0% EPSS
CVE-2026-43566 🟠 Łataj w tym tygodniu

OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carrying untrusted content. Attackers can exploit this by sending u…

9.1 CVSS
0.1% EPSS
CVE-2026-25770 🔴 Łataj teraz

Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, a privilege escalation vulnerability exists in the Wazuh Manager's clus…

9.1 CVSS
0.1% EPSS
CVE-2026-34177 🟠 Łataj w tym tygodniu

Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under the…

9.1 CVSS
0.1% EPSS
CVE-2026-22872 🔴 Łataj teraz

Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the namespace, this is …

9.1 CVSS
0.1% EPSS
CVE-2025-66024 🔴 Łataj teraz

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability arise…

9.0 CVSS
0.6% EPSS
CVE-2026-43578 🟠 Łataj w tym tygodniu

OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can exploit this by prov…

9.1 CVSS
0.1% EPSS
CVE-2026-41201 🟠 Łataj w tym tygodniu

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an attacker can achieve Full Account Takeover & Privilege…

9.1 CVSS
0.0% EPSS
CVE-2026-6388 🟠 Łataj w tym tygodniu

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting …

9.1 CVSS
0.0% EPSS
CVE-2026-41386 🟠 Łataj w tym tygodniu

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pai…

9.1 CVSS
0.0% EPSS
CVE-2026-9051 🟠 Łataj w tym tygodniu

There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or…

9.1 CVSS
0.0% EPSS
CVE-2026-32519 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2.

9.0 CVSS
0.1% EPSS
CVE-2026-48150 🟠 Łataj w tym tygodniu

Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAdmin middleware, which passes any user who is a builder for the app id in the x-budibase-app-id heade…

9.0 CVSS
0.1% EPSS
CVE-2026-33749 🟠 Łataj w tym tygodniu

n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated user with permission to create or modify workflows could craft a workflow that produces an HTML binary …

9.0 CVSS
0.0% EPSS
CVE-2026-40572 🔴 Łataj teraz

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address ranges into their add…

9.0 CVSS
0.0% EPSS
CVE-2023-4665 🟡 Monitoruj

Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9.

8.8 CVSS
0.8% EPSS
CVE-2026-26368 🟠 Łataj w tym tygodniu

eNet SMART HOME server 2.2.1 and 2.3.1 contains a missing authorization vulnerability in the resetUserPassword JSON-RPC method that allows any authenticated low-privileged user (UG_USER) to reset the password of arbitrar…

8.8 CVSS
0.5% EPSS
CVE-2026-25040 🟠 Łataj w tym tygodniu

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and including 3.26.3, a Creator-level user, who normally has no UI permission to invite users, can manipulate AP…

8.8 CVSS
0.5% EPSS
CVE-2024-32019 🟡 Monitoruj

Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of the Netdata Agent allows an attacker to run arbitrary programs with root permissions. The `ndsudo` to…

8.8 CVSS
0.5% EPSS
CVE-2026-57518 🟡 Monitoruj

Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to mi…

8.8 CVSS
0.5% EPSS
CVE-2026-4297 🟡 Monitoruj

The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capability check in the nc_setOption() function, which i…

8.8 CVSS
0.5% EPSS
CVE-2026-25497 🟡 Monitoruj

Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL API that allows an aut…

8.8 CVSS
0.4% EPSS
CVE-2026-25201 🟡 Monitoruj

An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1.

8.8 CVSS
0.4% EPSS
CVE-2025-2817 🟡 Monitoruj

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker…

8.8 CVSS
0.4% EPSS
CVE-2026-48889 🟡 Monitoruj

Subscriber Privilege Escalation in Amelia <= 2.3 versions.

8.8 CVSS
0.4% EPSS
CVE-2026-56010 🟡 Monitoruj

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

8.8 CVSS
0.4% EPSS
CVE-2021-38289 🟠 Łataj w tym tygodniu

An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allows attackers to view corporate information and SMTP server details, delete users, view roles, and oth…

8.8 CVSS
0.4% EPSS
CVE-2024-50504 🟡 Monitoruj

Incorrect Privilege Assignment vulnerability in webxmedia Bulk Change Role bulk-role-change allows Privilege Escalation.This issue affects Bulk Change Role: from n/a through <= 1.1.

8.8 CVSS
0.4% EPSS
CVE-2026-22683 🟡 Monitoruj

Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although…

8.8 CVSS
0.4% EPSS
CVE-2026-47342 🟡 Monitoruj
apps

A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to versio…

8.8 CVSS
0.3% EPSS
CVE-2026-53811 🟡 Monitoruj

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the …

8.8 CVSS
0.3% EPSS
CVE-2021-4331 🟡 Monitoruj

The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders f…

8.8 CVSS
0.3% EPSS
CVE-2026-34427 🟡 Monitoruj

Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows authenticated users to modify privileged fields on their own profile. Attackers can inject role_id=…

8.8 CVSS
0.3% EPSS
CVE-2024-7557 🟡 Monitoruj
os

A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option to protect models wit…

8.8 CVSS
0.3% EPSS
CVE-2024-50481 🟡 Monitoruj

Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege Escalation.This issue affects Bstone Demo Importer: from n/a through <= 1.0.1.

8.8 CVSS
0.3% EPSS
CVE-2026-39579 🟡 Monitoruj

Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.

8.8 CVSS
0.3% EPSS
CVE-2026-49780 🟡 Monitoruj

Customer Privilege Escalation in Dokan <= 5.0.2 versions.

8.8 CVSS
0.3% EPSS
CVE-2026-56008 🟡 Monitoruj

Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.

8.8 CVSS
0.3% EPSS
CVE-2024-49219 🟡 Monitoruj

Incorrect Privilege Assignment vulnerability in themexpo RS-Members rs-members allows Privilege Escalation.This issue affects RS-Members: from n/a through <= 1.0.3.

8.8 CVSS
0.3% EPSS
CVE-2024-50506 🟡 Monitoruj

Incorrect Privilege Assignment vulnerability in azexo Marketing Automation by AZEXO marketing-automation-by-azexo allows Privilege Escalation.This issue affects Marketing Automation by AZEXO: from n/a through <= 1.27.80.

8.8 CVSS
0.3% EPSS
CVE-2026-12448 🟡 Monitoruj
cloud

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)

8.8 CVSS
0.3% EPSS
CVE-2026-49111 🟡 Monitoruj

Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.

8.8 CVSS
0.2% EPSS
CVE-2026-24516 🟡 Monitoruj

A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner/actioner.go) processes metadata from the metadata service en…

8.8 CVSS
0.2% EPSS
CVE-2026-56038 🟡 Monitoruj

Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.

8.8 CVSS
0.2% EPSS
CVE-2022-4935 🟡 Monitoruj

The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to, and including, 3.4.11 due to missing capability checks on various AJAX actions. This makes it pos…

8.8 CVSS
0.2% EPSS
CVE-2026-41378 🟡 Monitoruj

OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired…

8.8 CVSS
0.2% EPSS
CVE-2023-4293 🟠 Łataj w tym tygodniu

The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' func…

8.8 CVSS
0.2% EPSS
CVE-2026-35639 🟡 Monitoruj

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device requests with broader operator scopes than the …

8.8 CVSS
0.2% EPSS
CVE-2026-41651 🟠 Łataj w tym tygodniu

PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a…

8.8 CVSS
0.2% EPSS
CVE-2023-51515 🟡 Monitoruj

Missing Authorization vulnerability in Undsgn Uncode Core allows Privilege Escalation.This issue affects Uncode Core: from n/a through 2.8.8.

8.8 CVSS
0.2% EPSS
CVE-2023-4664 🟡 Monitoruj

Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation. This issue affects Saphira Connect: before 9.

8.8 CVSS
0.2% EPSS
CVE-2026-12018 🟡 Monitoruj
cloud

Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

8.8 CVSS
0.2% EPSS
CVE-2024-49608 🟡 Monitoruj

Incorrect Privilege Assignment vulnerability in gerryworks GERRYWORKS Post by Mail gerryworks-post-by-mail allows Privilege Escalation.This issue affects GERRYWORKS Post by Mail: from n/a through <= 1.0.

8.8 CVSS
0.1% EPSS
CVE-2023-6009 🟡 Monitoruj

The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for aut…

8.8 CVSS
0.1% EPSS
CVE-2026-5967 🟡 Monitoruj

ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attackers with shell access can inject OS commands and execute them with root privileges.

8.8 CVSS
0.1% EPSS
CVE-2026-6226 🟡 Monitoruj

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary …

8.8 CVSS
0.1% EPSS
CVE-2026-32042 🟡 Monitoruj

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pairing requirements and self-assign elevated operator scopes including o…

8.8 CVSS
0.1% EPSS
CVE-2023-4153 🟡 Monitoruj

The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to a missing capability check on the 'w3dev_save_ban_user_settings_callback' function. This makes it po…

8.8 CVSS
0.1% EPSS
CVE-2021-4334 🟡 Monitoruj

The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. Thi…

8.8 CVSS
0.1% EPSS
CVE-2025-23528 🟡 Monitoruj

Incorrect Privilege Assignment vulnerability in Mosterd3d DD Roles dd-roles allows Privilege Escalation.This issue affects DD Roles: from n/a through <= 4.1.

8.8 CVSS
0.1% EPSS
CVE-2026-6228 🟡 Monitoruj

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism com…

8.8 CVSS
0.1% EPSS
CVE-2026-11272 🟡 Monitoruj
os

Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation v…

8.8 CVSS
0.1% EPSS
CVE-2026-11295 🟡 Monitoruj
cloud

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

8.8 CVSS
0.1% EPSS
CVE-2024-1138 🟡 Monitoruj

The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlser…

8.8 CVSS
0.1% EPSS
CVE-2023-3713 🟡 Monitoruj

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. Thi…

8.8 CVSS
0.1% EPSS
CVE-2023-3636 🟡 Monitoruj

The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for …

8.8 CVSS
0.1% EPSS
CVE-2025-14323 🟡 Monitoruj

Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

8.8 CVSS
0.1% EPSS
CVE-2025-58710 🟡 Monitoruj

Incorrect Privilege Assignment vulnerability in e-plugins Hotel Listing hotel-listing allows Privilege Escalation.This issue affects Hotel Listing: from n/a through <= 1.4.0.

8.8 CVSS
0.1% EPSS
CVE-2025-14328 🟡 Monitoruj

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

8.8 CVSS
0.1% EPSS
CVE-2025-14329 🟡 Monitoruj

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

8.8 CVSS
0.1% EPSS
CVE-2024-31498 🟡 Monitoruj

Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windows can open as Administrator.

8.8 CVSS
0.1% EPSS
CVE-2026-41404 🟡 Monitoruj

OpenClaw before 2026.3.31 contains an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that allows operator.admin privilege escalation. Attackers can exploit this by declaring operator scopes …

8.8 CVSS
0.1% EPSS
CVE-2026-11108 🟡 Monitoruj
cloud

Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

8.8 CVSS
0.1% EPSS