CVE z tagiem privilege-escalation — 200 wyników. ← Wszystkie tagi

CVE-2024-0012 🔴 Łataj teraz KEV
network

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative act…

CVE-2021-34523 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Elevation of Privilege Vulnerability

9.0 CVSS
100.0% EPSS
CVE-2021-4034 🔴 Łataj teraz KEV
os

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined polic…

7.8 CVSS
94.9% EPSS
CVE-2015-0016 🔴 Łataj teraz KEV
appscloud

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Window…

CVE-2024-9474 🔴 Łataj teraz KEV
network

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW an…

7.2 CVSS
94.8% EPSS
CVE-2016-0099 🔴 Łataj teraz KEV
appscloud

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly …

7.8 CVSS
90.4% EPSS
CVE-2017-0213 🔴 Łataj teraz KEV
appscloud

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016…

7.3 CVSS
92.7% EPSS
CVE-2016-7255 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server…

7.8 CVSS
89.4% EPSS
CVE-2014-1812 🔴 Łataj teraz KEV
appscloud

The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of pass…

8.8 CVSS
83.1% EPSS
CVE-2014-4113 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Go…

7.8 CVSS
82.4% EPSS
CVE-2022-41080 🔴 Łataj teraz KEV
appscloud

Microsoft Exchange Server Elevation of Privilege Vulnerability

8.8 CVSS
77.3% EPSS
CVE-2016-0040 🔴 Łataj teraz KEV
appscloud

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

7.8 CVSS
78.9% EPSS
CVE-2021-1732 🔴 Łataj teraz KEV
appscloud

Windows Win32k Elevation of Privilege Vulnerability

7.8 CVSS
77.8% EPSS
CVE-2021-42287 🔴 Łataj teraz KEV
appscloud

Active Directory Domain Services Elevation of Privilege Vulnerability

7.5 CVSS
75.8% EPSS
CVE-2019-1458 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

7.8 CVSS
73.9% EPSS
CVE-2021-42278 🔴 Łataj teraz KEV
appscloud

Active Directory Domain Services Elevation of Privilege Vulnerability

7.5 CVSS
72.0% EPSS
CVE-2018-8453 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 20…

7.8 CVSS
70.0% EPSS
CVE-2018-8120 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows…

7.0 CVSS
73.7% EPSS
CVE-2021-36934 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully explo…

7.8 CVSS
67.3% EPSS
CVE-2017-0101 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607;…

7.8 CVSS
67.2% EPSS
CVE-2011-2005 🔴 Łataj teraz KEV
appscloud

afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted…

7.8 CVSS
67.1% EPSS
CVE-2024-30088 🔴 Łataj teraz KEV
appscloud

Windows Kernel Elevation of Privilege Vulnerability

7.0 CVSS
68.2% EPSS
CVE-2024-21338 🔴 Łataj teraz KEV
appscloud

Windows Kernel Elevation of Privilege Vulnerability

7.8 CVSS
59.8% EPSS
CVE-2015-1701 🔴 Łataj teraz KEV
appscloud

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win…

7.8 CVSS
56.2% EPSS
CVE-2014-4123 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a differ…

8.8 CVSS
50.6% EPSS
CVE-2014-4077 🔴 Łataj teraz KEV
appscloud

Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandb…

7.8 CVSS
50.8% EPSS
CVE-2022-21882 🔴 Łataj teraz KEV
appscloud

Win32k Elevation of Privilege Vulnerability

7.0 CVSS
54.5% EPSS
CVE-2020-1054 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code…

7.0 CVSS
54.2% EPSS
CVE-2017-0210 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain…

8.8 CVSS
42.1% EPSS
CVE-2016-3309 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local use…

7.8 CVSS
46.3% EPSS
CVE-2020-0787 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privileg…

7.8 CVSS
42.5% EPSS
CVE-2014-2817 🔴 Łataj teraz KEV
appscloud

Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

8.8 CVSS
26.4% EPSS
CVE-2019-1405 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

7.8 CVSS
29.9% EPSS
CVE-2026-48172 🔴 Łataj teraz KEV

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /v…

9.8 CVSS
18.9% EPSS
CVE-2024-1086 🔴 Łataj teraz KEV

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within t…

7.8 CVSS
28.1% EPSS
CVE-2021-36948 🔴 Łataj teraz KEV
appscloud

Windows Update Medic Service Elevation of Privilege Vulnerability

7.8 CVSS
26.7% EPSS
CVE-2015-1769 🔴 Łataj teraz KEV
appscloud

Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which…

6.6 CVSS
31.8% EPSS
CVE-2017-0001 🔴 Łataj teraz KEV
appscloud

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all…

7.8 CVSS
25.4% EPSS
CVE-2024-35250 🔴 Łataj teraz KEV
appscloud

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

7.8 CVSS
25.2% EPSS
CVE-2021-34484 🔴 Łataj teraz KEV
appscloud

Windows User Profile Service Elevation of Privilege Vulnerability

7.8 CVSS
21.7% EPSS
CVE-2024-49039 🔴 Łataj teraz KEV
appscloud

Windows Task Scheduler Elevation of Privilege Vulnerability

8.8 CVSS
13.7% EPSS
CVE-2017-0263 🔴 Łataj teraz KEV
appscloud

The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local…

7.8 CVSS
18.5% EPSS
CVE-2015-2360 🔴 Łataj teraz KEV
appscloud

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Wi…

8.8 CVSS
11.6% EPSS
CVE-2015-2546 🔴 Łataj teraz KEV
appscloud

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local user…

8.2 CVSS
10.9% EPSS
CVE-2024-55550 🔴 Łataj teraz KEV

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated …

2.7 CVSS
38.1% EPSS
CVE-2021-38648 🔴 Łataj teraz KEV
appscloud

Open Management Infrastructure Elevation of Privilege Vulnerability

7.8 CVSS
11.4% EPSS
CVE-2023-23376 🔴 Łataj teraz KEV
appscloud

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8 CVSS
10.8% EPSS
CVE-2023-36424 🔴 Łataj teraz KEV
appscloud

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8 CVSS
10.7% EPSS
CVE-2021-33771 🔴 Łataj teraz KEV
appscloud

Windows Kernel Elevation of Privilege Vulnerability

7.8 CVSS
10.2% EPSS
CVE-2021-34486 🔴 Łataj teraz KEV
appscloud

Windows Event Tracing Elevation of Privilege Vulnerability

7.8 CVSS
9.3% EPSS
CVE-2017-0005 🔴 Łataj teraz KEV
appscloud

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 all…

7.8 CVSS
8.0% EPSS
CVE-2021-41379 🔴 Łataj teraz KEV
appscloud

Windows Installer Elevation of Privilege Vulnerability

5.5 CVSS
19.4% EPSS
CVE-2024-38014 🔴 Łataj teraz KEV
appscloud

Windows Installer Elevation of Privilege Vulnerability

7.8 CVSS
6.3% EPSS
CVE-2019-1069 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim …

7.8 CVSS
6.1% EPSS
CVE-2016-0167 🔴 Łataj teraz KEV
appscloud

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to g…

7.8 CVSS
6.1% EPSS
CVE-2016-0165 🔴 Łataj teraz KEV
appscloud

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to g…

7.8 CVSS
6.0% EPSS
CVE-2021-31979 🔴 Łataj teraz KEV
appscloud

Windows Kernel Elevation of Privilege Vulnerability

7.8 CVSS
4.5% EPSS
CVE-2021-36955 🔴 Łataj teraz KEV
appscloud

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8 CVSS
4.0% EPSS
CVE-2019-1385 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated att…

7.8 CVSS
3.6% EPSS
CVE-2021-43226 🔴 Łataj teraz KEV
appscloud

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8 CVSS
3.1% EPSS
CVE-2020-0638 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Noti…

7.8 CVSS
3.0% EPSS
CVE-2022-41125 🔴 Łataj teraz KEV
appscloud

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

7.8 CVSS
3.0% EPSS
CVE-2015-6175 🔴 Łataj teraz KEV
appscloud

The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability."

7.8 CVSS
2.8% EPSS
CVE-2021-38645 🔴 Łataj teraz KEV
appscloud

Open Management Infrastructure Elevation of Privilege Vulnerability

7.8 CVSS
2.7% EPSS
CVE-2022-41073 🔴 Łataj teraz KEV
appscloud

Windows Print Spooler Elevation of Privilege Vulnerability

7.8 CVSS
2.4% EPSS
CVE-2019-1130 🔴 Łataj teraz KEV
appscloud

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.

7.8 CVSS
2.3% EPSS
CVE-2021-38649 🔴 Łataj teraz KEV
appscloud

Open Management Infrastructure Elevation of Privilege Vulnerability

7.0 CVSS
2.9% EPSS
CVE-2023-36899 🟠 Łataj w tym tygodniu
appscloud

ASP.NET Elevation of Privilege Vulnerability

8.8 CVSS
77.1% EPSS
CVE-2024-50483 🔴 Łataj teraz

Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.This issue affects Meetup: from n/a through <= 0.1.

9.8 CVSS
54.0% EPSS
CVE-2023-3277 🔴 Łataj teraz

The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows un…

9.8 CVSS
38.7% EPSS
CVE-2010-1225 🔴 Łataj teraz
appscloud

The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restric…

9.3 CVSS
38.9% EPSS
CVE-2024-50475 🔴 Łataj teraz

Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affects Signup Page: from n/a through <= 1.0.

9.8 CVSS
32.0% EPSS
CVE-2024-50476 🟠 Łataj w tym tygodniu

Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.

9.8 CVSS
24.7% EPSS
CVE-2024-50485 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issue affects Exam Matrix: from n/a through <= 1.5.

9.8 CVSS
21.9% EPSS
CVE-2023-2833 🟠 Łataj w tym tygodniu

The ReviewX plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.13 due to insufficient restriction on the 'rx_set_screen_options' function. This makes it possible for authenti…

8.8 CVSS
26.8% EPSS
CVE-2023-3124 🟠 Łataj w tym tygodniu

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible…

8.8 CVSS
26.0% EPSS
CVE-2026-8732 🟠 Łataj w tym tygodniu

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being regis…

9.8 CVSS
19.3% EPSS
CVE-2023-6246 🟠 Łataj w tym tygodniu

A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or …

CVE-2023-2916 🟡 Monitoruj

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-…

7.5 CVSS
29.5% EPSS
CVE-2022-4939 🟠 Łataj w tym tygodniu

THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that contro…

9.8 CVSS
7.3% EPSS
CVE-2020-1048 🟡 Monitoruj
appscloud

An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary …

7.8 CVSS
16.5% EPSS
CVE-2024-30085 🟡 Monitoruj
appscloud

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

7.8 CVSS
15.1% EPSS
CVE-2023-5178 🟡 Monitoruj
os

A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-a…

8.8 CVSS
9.3% EPSS
CVE-2022-25090 🟠 Łataj w tym tygodniu

Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.

8.1 CVSS
11.0% EPSS
CVE-2025-4334 🟠 Łataj w tym tygodniu

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during …

9.8 CVSS
2.1% EPSS
CVE-2023-21709 🟠 Łataj w tym tygodniu
appscloud

Microsoft Exchange Server Elevation of Privilege Vulnerability

9.8 CVSS
2.0% EPSS
CVE-2023-35175 🟠 Łataj w tym tygodniu

Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.

9.8 CVSS
1.8% EPSS
CVE-2026-39907 🔴 Łataj teraz

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allo…

10.0 CVSS
0.6% EPSS
CVE-2026-48331 🟠 Łataj w tym tygodniu

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

10.0 CVSS
0.5% EPSS
CVE-2024-21401 🟠 Łataj w tym tygodniu
appscloud

Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability

9.8 CVSS
1.5% EPSS
CVE-2026-47938 🟠 Łataj w tym tygodniu

Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require…

10.0 CVSS
0.4% EPSS
CVE-2024-10035 🟠 Łataj w tym tygodniu

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Comma…

9.8 CVSS
1.3% EPSS
CVE-2026-39906 🔴 Łataj teraz

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a Win…

10.0 CVSS
0.2% EPSS
CVE-2026-44962 🟠 Łataj w tym tygodniu

Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated,…

9.9 CVSS
0.7% EPSS
CVE-2026-33579 🟠 Łataj w tym tygodniu

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without adm…

9.9 CVSS
0.6% EPSS
CVE-2024-2172 🟠 Łataj w tym tygodniu

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all version…

9.8 CVSS
1.1% EPSS
CVE-2026-73268 🟠 Łataj w tym tygodniu

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possibl…

9.9 CVSS
0.5% EPSS
CVE-2026-56142 🟠 Łataj w tym tygodniu

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible

9.9 CVSS
0.4% EPSS
CVE-2026-4003 🟠 Łataj w tym tygodniu

The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. This is due to a flawed authorization logic check in the usersp…

9.8 CVSS
0.9% EPSS
CVE-2023-27971 🟠 Łataj w tym tygodniu

Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.

9.8 CVSS
0.9% EPSS
CVE-2026-42368 🟠 Łataj w tym tygodniu

A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpag…

9.9 CVSS
0.4% EPSS
CVE-2026-47724 🟠 Łataj w tym tygodniu

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codeb…

9.9 CVSS
0.4% EPSS
CVE-2026-72508 🟠 Łataj w tym tygodniu

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subsc…

9.9 CVSS
0.3% EPSS
CVE-2026-48086 🟠 Łataj w tym tygodniu

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT re…

9.9 CVSS
0.3% EPSS
CVE-2026-73269 🟠 Łataj w tym tygodniu

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This a…

9.9 CVSS
0.3% EPSS
CVE-2026-8809 🟠 Łataj w tym tygodniu

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_p…

9.8 CVSS
0.8% EPSS
CVE-2026-72526 🟠 Łataj w tym tygodniu

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenan…

9.9 CVSS
0.3% EPSS
CVE-2023-39004 🔴 Łataj teraz

Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which…

9.8 CVSS
0.8% EPSS
CVE-2026-49252 🟠 Łataj w tym tygodniu

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential priv…

9.9 CVSS
0.3% EPSS
CVE-2026-70496 🟠 Łataj w tym tygodniu

A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, …

9.9 CVSS
0.3% EPSS
CVE-2026-50656 🟡 Monitoruj
appscloud

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;RoguePlanet &quot;.

7.8 CVSS
10.8% EPSS
CVE-2026-35031 🟠 Łataj w tym tygodniu

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, all…

9.9 CVSS
0.2% EPSS
CVE-2026-32922 🟠 Łataj w tym tygodniu

OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to mint tokens with broader scopes by failing to constrain newly minted scope…

9.9 CVSS
0.2% EPSS
CVE-2026-12415 🟠 Łataj w tym tygodniu

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is …

9.8 CVSS
0.7% EPSS
CVE-2021-4360 🔴 Łataj teraz

The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for atta…

9.9 CVSS
0.1% EPSS
CVE-2026-11551 🟠 Łataj w tym tygodniu

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updati…

9.8 CVSS
0.6% EPSS
CVE-2023-36900 🟡 Monitoruj
appscloud

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.8 CVSS
10.6% EPSS
CVE-2026-33945 🟠 Łataj w tym tygodniu

Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0,…

9.9 CVSS
0.1% EPSS
CVE-2026-7813 🟠 Łataj w tym tygodniu

Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules. Multiple endpoints fetched user-owned objects without filtering by the r…

9.9 CVSS
0.1% EPSS
CVE-2026-34571 🔴 Łataj teraz

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerab…

9.9 CVSS
0.1% EPSS
CVE-2024-37927 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in NooTheme Jobmonster noo-jobmonster allows Privilege Escalation.This issue affects Jobmonster: from n/a through <= 4.7.5.

9.8 CVSS
0.5% EPSS
CVE-2026-30269 🔴 Łataj teraz

Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is accepted by the update…

9.9 CVSS
0.0% EPSS
CVE-2026-41329 🟠 Łataj w tym tygodniu

OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulation. Attackers can exploit improper conte…

9.9 CVSS
0.0% EPSS
CVE-2026-20744 🟠 Łataj w tym tygodniu

The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.

9.8 CVSS
0.5% EPSS
CVE-2026-40920 🟠 Łataj w tym tygodniu
apps

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

9.8 CVSS
0.5% EPSS
CVE-2026-19598 🟠 Łataj w tym tygodniu

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin …

9.8 CVSS
0.5% EPSS
CVE-2026-7284 🟠 Łataj w tym tygodniu

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle…

9.8 CVSS
0.5% EPSS
CVE-2026-5118 🟠 Łataj w tym tygodniu

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user …

9.8 CVSS
0.5% EPSS
CVE-2026-27960 🟠 Łataj w tym tygodniu

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticate…

9.8 CVSS
0.5% EPSS
CVE-2026-57813 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.

9.8 CVSS
0.5% EPSS
CVE-2026-30118 🟠 Łataj w tym tygodniu

scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers to force the backend…

9.8 CVSS
0.5% EPSS
CVE-2026-48333 🟠 Łataj w tym tygodniu

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of th…

9.8 CVSS
0.5% EPSS
CVE-2025-69179 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.

9.8 CVSS
0.4% EPSS
CVE-2026-12417 🟠 Łataj w tym tygodniu

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_pa…

9.8 CVSS
0.4% EPSS
CVE-2026-18432 🟠 Łataj w tym tygodniu

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `curre…

9.8 CVSS
0.4% EPSS
CVE-2026-56654 🟠 Łataj w tym tygodniu

Privilege Escalation via Access Token Scope Escalation in API

9.8 CVSS
0.4% EPSS
CVE-2021-47932 🟠 Łataj w tym tygodniu

WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send …

9.8 CVSS
0.4% EPSS
CVE-2026-2777 🟠 Łataj w tym tygodniu

Privilege escalation in the Messaging System component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

9.8 CVSS
0.4% EPSS
CVE-2026-39583 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.

9.8 CVSS
0.4% EPSS
CVE-2026-56028 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions.

9.8 CVSS
0.4% EPSS
CVE-2025-32491 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO – On-site SEO rankology-seo-all-in-one-seo-analytics allows Privilege Escalation.This issue affects Rankology SEO – On-site SEO: from n/a through <=…

9.8 CVSS
0.4% EPSS
CVE-2026-14956 🟠 Łataj w tym tygodniu

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action,…

9.8 CVSS
0.4% EPSS
CVE-2024-49322 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in CodePassenger Job Board Manager for WordPress jemployee allows Privilege Escalation.This issue affects Job Board Manager for WordPress: from n/a through <= 1.0.

9.8 CVSS
0.3% EPSS
CVE-2026-56030 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-56033 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-28005 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-65507 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-61967 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-66424 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-74985 🟠 Łataj w tym tygodniu

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

9.8 CVSS
0.3% EPSS
CVE-2026-34901 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-12073 🟠 Łataj w tym tygodniu

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validat…

9.8 CVSS
0.3% EPSS
CVE-2024-49217 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in madiriaashish Adding drop down roles in registration user-drop-down-roles-in-registration allows Privilege Escalation.This issue affects Adding drop down roles in registrat…

9.8 CVSS
0.3% EPSS
CVE-2026-57692 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.

9.8 CVSS
0.3% EPSS
CVE-2026-15982 🟠 Łataj w tym tygodniu

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing…

9.8 CVSS
0.3% EPSS
CVE-2026-14446 🟠 Łataj w tym tygodniu

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

9.8 CVSS
0.3% EPSS
CVE-2026-65884 🟠 Łataj w tym tygodniu

Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permis…

9.8 CVSS
0.3% EPSS
CVE-2026-66662 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-73347 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-73390 🟠 Łataj w tym tygodniu

Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

9.8 CVSS
0.3% EPSS
CVE-2026-8181 🟠 Łataj w tym tygodniu

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value h…

9.8 CVSS
0.3% EPSS
CVE-2023-4404 🟠 Łataj w tym tygodniu

The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it pos…

9.8 CVSS
0.2% EPSS
CVE-2024-56000 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/a through < 5.4.0.

9.8 CVSS
0.2% EPSS
CVE-2026-6510 🟠 Łataj w tym tygodniu

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the …

9.8 CVSS
0.2% EPSS
CVE-2023-2987 🟠 Łataj w tym tygodniu

The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This m…

9.8 CVSS
0.2% EPSS
CVE-2026-4880 🟠 Łataj w tym tygodniu

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication in all versions up t…

9.8 CVSS
0.1% EPSS
CVE-2025-67112 🟠 Łataj w tym tygodniu

Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote authenticated users to decrypt…

9.8 CVSS
0.1% EPSS
CVE-2026-24178 🟠 Łataj w tym tygodniu
os

NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of thi…

9.8 CVSS
0.1% EPSS
CVE-2026-8206 🟠 Łataj w tym tygodniu

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbit…

9.8 CVSS
0.1% EPSS
CVE-2023-51484 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in wp-buy Login as User or Customer (User Switching) login-as-customer-or-user allows Privilege Escalation.This issue affects Login as User or Customer (User Switching): from …

9.8 CVSS
0.1% EPSS
CVE-2023-3374 🟠 Łataj w tym tygodniu

Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation.This issue affects Bookreen: before 3.0.0.

9.8 CVSS
0.1% EPSS
CVE-2025-13618 🟠 Łataj w tym tygodniu

The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not properly restricting the roles that users can register with in the mento…

9.8 CVSS
0.1% EPSS
CVE-2026-4038 🟠 Łataj w tym tygodniu

The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due to a missing capability check on the 'aiomatic_call_ai_function_realtime' function in all versions u…

9.8 CVSS
0.1% EPSS
CVE-2026-24971 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8.

9.8 CVSS
0.1% EPSS
CVE-2026-24968 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30.

9.8 CVSS
0.1% EPSS
CVE-2026-27051 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0.

9.8 CVSS
0.1% EPSS
CVE-2026-32520 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through <= 1.0.4.

9.8 CVSS
0.1% EPSS
CVE-2026-2782 🟠 Łataj w tym tygodniu

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

9.8 CVSS
0.1% EPSS
CVE-2026-9094 🟠 Łataj w tym tygodniu

Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the t…

9.8 CVSS
0.1% EPSS
CVE-2026-32987 🟠 Łataj w tym tygodniu

OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to esc…

9.8 CVSS
0.0% EPSS
CVE-2026-42731 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.

9.8 CVSS
0.0% EPSS
CVE-2026-42758 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253.

9.8 CVSS
0.0% EPSS
CVE-2025-6254 🟠 Łataj w tym tygodniu

The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles tha…

9.8 CVSS
0.0% EPSS
CVE-2026-49060 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.

9.8 CVSS
0.0% EPSS
CVE-2016-20024 🟠 Łataj w tym tygodniu

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the Z…

9.8 CVSS
0.0% EPSS
CVE-2026-30793 🔴 Łataj teraz
os

Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation. This…

9.8 CVSS
0.0% EPSS
CVE-2026-27542 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Captu…

9.8 CVSS
0.0% EPSS
CVE-2026-4717 🟠 Łataj w tym tygodniu

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

9.8 CVSS
0.0% EPSS
CVE-2026-2780 🟠 Łataj w tym tygodniu

Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 148, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

9.8 CVSS
0.0% EPSS
CVE-2025-53209 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.

9.8 CVSS
0.0% EPSS
CVE-2026-48898 🟠 Łataj w tym tygodniu
apps

An improper access check allows privilege escalation through the com_users batch task.

9.8 CVSS
0.0% EPSS
CVE-2026-48899 🟠 Łataj w tym tygodniu
apps

An improper access check allows privilege escalation through the com_users batch task.

9.8 CVSS
0.0% EPSS
CVE-2026-42680 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.

9.8 CVSS
0.0% EPSS
CVE-2026-48879 🟠 Łataj w tym tygodniu

Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

9.8 CVSS
0.0% EPSS
CVE-2023-35359 🟡 Monitoruj
appscloud

Windows Kernel Elevation of Privilege Vulnerability

7.8 CVSS
9.9% EPSS
CVE-2026-39821 🟠 Łataj w tym tygodniu

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an erro…

9.6 CVSS
0.7% EPSS
CVE-2024-30087 🟡 Monitoruj
appscloud

Win32k Elevation of Privilege Vulnerability

7.8 CVSS
9.5% EPSS
CVE-2026-55518 🟠 Łataj w tym tygodniu

Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new …

9.6 CVSS
0.3% EPSS
CVE-2026-42235 🟠 Łataj w tym tygodniu

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user aut…

9.6 CVSS
0.1% EPSS
CVE-2025-7743 🟠 Łataj w tym tygodniu

Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalation. This issue affects Omaspot: before 12.09.2025.

9.6 CVSS
0.0% EPSS