276 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-76669 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful expl | CRITICAL | 9.9 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-76670 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful expl | CRITICAL | 9.9 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-83282 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | CRITICAL | 9.9 | 21%ile | NVD | 2026-09-15 |
| CVE-2026-87172 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.9 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-7374 | Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability | CRITICAL | 9.9 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2026-89610 | In the Linux kernel, the following vulnerability has been resolved: ntfs: verify run length exceeding volume boundary | CRITICAL | 9.8 | 45%ile | NVD | 2026-09-11 |
| CVE-2026-85681 | The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it ma | CRITICAL | 9.8 | 20%ile | NVD | 2026-09-12 |
| CVE-2026-73470 | Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not | CRITICAL | 9.8 | 40%ile | NVD | 2026-09-14 |
| CVE-2026-12793 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versi | CRITICAL | 9.8 | 33%ile | NVD | 2026-09-16 |
| CVE-2026-87186 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.6 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-21391 | An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID | CRITICAL | 9.5 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-92957 | vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) | CRITICAL | 9.4 | 41%ile | NVD | 2026-09-17 |
| CVE-2026-91104 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | CRITICAL | 9.3 | 52%ile | NVD | 2026-09-16 |
| CVE-2026-91106 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | CRITICAL | 9.3 | 50%ile | NVD | 2026-09-16 |
| CVE-2026-24834 | Kata Container to Guest micro VM privilege escalation | CRITICAL | 9.3 | 13%ile | Microsoft | 2026-02-10 |
| CVE-2026-83196 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | CRITICAL | 9.1 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-83260 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Event Java PX). The supported version | CRITICAL | 9.1 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-83268 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | CRITICAL | 9.1 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-87189 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-87214 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-61549 | Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_op | CRITICAL | 9.0 | 6%ile | NVD | 2026-09-15 |
| CVE-2026-62102 | Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions. | HIGH | 8.8 | 25%ile | NVD | 2026-09-11 |
| CVE-2026-62106 | Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions. | HIGH | 8.8 | 25%ile | NVD | 2026-09-11 |
| CVE-2026-87759 | The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a p | HIGH | 8.8 | 14%ile | NVD | 2026-09-12 |
| CVE-2026-15451 | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and inc | HIGH | 8.8 | 16%ile | NVD | 2026-09-12 |
| CVE-2026-14805 | The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-92006 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 29%ile | NVD | 2026-09-15 |
| CVE-2026-92007 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-92008 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-92009 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-92010 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-92011 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-92012 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-92013 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-92014 | Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Fir | HIGH | 8.8 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-92015 | Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Fi | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-92017 | Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115 | HIGH | 8.8 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-92020 | Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was f | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-92033 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156. | HIGH | 8.8 | 11%ile | NVD | 2026-09-15 |
| CVE-2026-92043 | Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in | HIGH | 8.8 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-92047 | Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, T | HIGH | 8.8 | 15%ile | NVD | 2026-09-15 |
| CVE-2026-92052 | Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in | HIGH | 8.8 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-92053 | Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 15 | HIGH | 8.8 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-92054 | Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbir | HIGH | 8.8 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-92055 | Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderb | HIGH | 8.8 | 16%ile | NVD | 2026-09-15 |
| CVE-2026-92062 | Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, T | HIGH | 8.8 | 15%ile | NVD | 2026-09-15 |
| CVE-2026-92073 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153. | HIGH | 8.8 | 15%ile | NVD | 2026-09-15 |
| CVE-2026-16140 | OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an e | HIGH | 8.8 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-40058 | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability on | HIGH | 8.8 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-79411 | Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated ba | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-76677 | A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could all | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-83119 | Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Internal Operations). Suppor | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-83120 | Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versio | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-83121 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-83148 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-83168 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Inter | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-83189 | Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supp | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-83194 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-83212 | Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-83271 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21 | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-83301 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Service Adm | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-83306 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supp | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-83315 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-83329 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-83331 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-83335 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics S | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-83338 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Inter | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-83340 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versi | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-83348 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21 | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-83410 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-83411 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar | HIGH | 8.8 | 21%ile | NVD | 2026-09-15 |
| CVE-2026-83423 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported v | HIGH | 8.8 | 21%ile | NVD | 2026-09-15 |
| CVE-2026-83444 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-83445 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Inte | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-83454 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Interna | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-83456 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations) | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-83479 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported ve | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-87150 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supporte | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-87155 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-87162 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componen | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-87163 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-87165 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componen | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-87179 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-87180 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-87181 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-87182 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-87185 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-87187 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 11%ile | NVD | 2026-09-15 |
| CVE-2026-87201 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 21%ile | NVD | 2026-09-15 |
| CVE-2026-87202 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 21%ile | NVD | 2026-09-15 |
| CVE-2026-87204 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-87224 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-87226 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 21%ile | NVD | 2026-09-15 |
| CVE-2026-87227 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 33%ile | NVD | 2026-09-15 |
| CVE-2026-87238 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-88904 | The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the | HIGH | 8.8 | 14%ile | NVD | 2026-09-17 |
| CVE-2026-12954 | The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including | HIGH | 8.8 | 39%ile | NVD | 2026-09-18 |
| CVE-2026-55887 | MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway Y | HIGH | 8.7 | 10%ile | NVD | 2026-09-15 |
| CVE-2026-88817 | An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an exi | HIGH | 8.7 | 20%ile | NVD | 2026-09-16 |
| CVE-2026-87273 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 8.6 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-92716 | Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint tha | HIGH | 8.6 | 24%ile | NVD | 2026-09-16 |
| CVE-2026-91098 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | HIGH | 8.6 | 50%ile | NVD | 2026-09-16 |
| CVE-2026-91105 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | HIGH | 8.6 | 50%ile | NVD | 2026-09-16 |
| CVE-2026-90493 | A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is | HIGH | 8.5 | 1%ile | NVD | 2026-09-13 |
| CVE-2026-12518 | A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privile | HIGH | 8.5 | 1%ile | NVD | 2026-09-14 |
| CVE-2026-83272 | Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 19.3-19. | HIGH | 8.5 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-83451 | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.5 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-91102 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | HIGH | 8.4 | 16%ile | NVD | 2026-09-16 |
| CVE-2026-92958 | vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard toge | HIGH | 8.4 | 20%ile | NVD | 2026-09-17 |
| CVE-2026-65354 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golde | HIGH | 8.2 | 3%ile | NVD | 2026-09-14 |
| CVE-2026-83169 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues). | HIGH | 8.1 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-83191 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 8.1 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-83192 | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are | HIGH | 8.1 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-83245 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-83246 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-83254 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-83255 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-83256 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-83258 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-83286 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 8.1 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-83299 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics W | HIGH | 8.1 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-83351 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3 | HIGH | 8.1 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-83464 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server | HIGH | 8.1 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-87231 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.1 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-85530 | The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value | HIGH | 8.1 | 30%ile | NVD | 2026-09-16 |
| CVE-2026-81442 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerabilit | HIGH | 8.1 | 32%ile | NVD | 2026-09-17 |
| CVE-2026-56668 | ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange | HIGH | 8.1 | 35%ile | GitHub | 2026-09-14 |
| CVE-2026-54330 | Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation | HIGH | 8.1 | 8%ile | Microsoft | 2026-08-11 |
| CVE-2026-55225 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. I | HIGH | 8.0 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-83170 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported | HIGH | 8.0 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-83450 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supporte | HIGH | 8.0 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-83483 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis) | HIGH | 8.0 | 30%ile | NVD | 2026-09-15 |
| CVE-2026-87164 | Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supp | HIGH | 8.0 | 12%ile | NVD | 2026-09-15 |
| CVE-2026-87245 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.0 | 11%ile | NVD | 2026-09-15 |
| CVE-2026-89579 | In the Linux kernel, the following vulnerability has been resolved: bpf: Harden bloom filter sizing and indexing on 32- | HIGH | 7.8 | 6%ile | NVD | 2026-09-11 |
| CVE-2026-90894 | Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_s | HIGH | 7.8 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-19624 | A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and v | HIGH | 7.8 | 3%ile | NVD | 2026-09-14 |
| CVE-2026-92180 | pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vul | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83118 | Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83147 | Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). T | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83211 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83214 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.8 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-83216 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.8 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-83247 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.8 | 6%ile | NVD | 2026-09-15 |
| CVE-2026-83249 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.8 | 1%ile | NVD | 2026-09-15 |
| CVE-2026-83253 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.8 | 3%ile | NVD | 2026-09-15 |
| CVE-2026-83288 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83290 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83291 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83293 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: FNDN). Th | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83294 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.8 | 6%ile | NVD | 2026-09-15 |
| CVE-2026-83317 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Installatio | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83336 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics S | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83337 | Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Remote | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83342 | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Sys | HIGH | 7.8 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-83353 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte | HIGH | 7.8 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-83420 | Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-87216 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.8 | 3%ile | NVD | 2026-09-15 |
| CVE-2026-87268 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-87269 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.8 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-87270 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.8 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-87271 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-87272 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-89791 | In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when perf mmap() revival r | HIGH | 7.8 | 4%ile | NVD | 2026-09-16 |
| CVE-2026-90046 | In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP P | HIGH | 7.8 | 4%ile | NVD | 2026-09-16 |
| CVE-2026-87886 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin | HIGH | 7.8 | 21%ile | NVD | 2026-09-17 |
| CVE-2026-46655 | virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits | HIGH | 7.8 | — | NVD | 2026-09-18 |
| CVE-2026-72693 | Kbd: local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login | HIGH | 7.8 | 1%ile | Microsoft | 2026-08-11 |
| CVE-2026-12505 | Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-76642 | util-linux libmount Privilege Escalation via Failed Mount Helper | HIGH | 7.8 | 7%ile | Microsoft | 2026-09-08 |
| ionstack-2026 | IonStack Part 2: Linux kernel io_uring privilege escalation exploit chain | HIGH | 7.8 | — | Featured | 2026-07-07 |
| CVE-2026-65831 | ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with lang | HIGH | 7.7 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-87183 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.7 | 5%ile | NVD | 2026-09-15 |
| CVE-2026-54087 | EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFie | HIGH | 7.6 | 23%ile | NVD | 2026-09-14 |
| CVE-2026-54175 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | HIGH | 7.6 | 32%ile | NVD | 2026-09-14 |
| CVE-2026-92616 | FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege att | HIGH | 7.6 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-86406 | The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a mem | HIGH | 7.5 | 9%ile | NVD | 2026-09-13 |
| CVE-2026-75983 | The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privile | HIGH | 7.5 | 35%ile | NVD | 2026-09-15 |
| CVE-2026-83114 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported vers | HIGH | 7.5 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-83241 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.5 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-83257 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.5 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-83262 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). | HIGH | 7.5 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-83263 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). | HIGH | 7.5 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-83289 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics W | HIGH | 7.5 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-83292 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.5 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-83295 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentatio | HIGH | 7.5 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-83296 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). | HIGH | 7.5 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-83318 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions th | HIGH | 7.5 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-83323 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.5 | 1%ile | NVD | 2026-09-15 |
| CVE-2026-83415 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar | HIGH | 7.5 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-83463 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server | HIGH | 7.5 | 15%ile | NVD | 2026-09-15 |
| CVE-2026-83489 | Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Onboarding | HIGH | 7.5 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-87139 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.5 | 17%ile | NVD | 2026-09-15 |
| CVE-2026-87140 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.5 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-87190 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-87203 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-87237 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-87247 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 15%ile | NVD | 2026-09-15 |
| CVE-2026-85128 | The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration | HIGH | 7.5 | 8%ile | NVD | 2026-09-17 |
| CVE-2026-50605 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insu | HIGH | 7.4 | 1%ile | NVD | 2026-09-17 |
| CVE-2026-50609 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. | HIGH | 7.4 | 1%ile | NVD | 2026-09-17 |
| CVE-2026-50610 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense d | HIGH | 7.4 | 1%ile | NVD | 2026-09-17 |
| CVE-2026-75092 | A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). | HIGH | 7.3 | 3%ile | NVD | 2026-09-15 |
| CVE-2026-83190 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.3 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-83193 | Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: Life Sciences). Supported ver | HIGH | 7.3 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-12080 | Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys | HIGH | 7.3 | 8%ile | Microsoft | 2026-07-14 |
| CVE-2026-77752 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary | HIGH | 7.2 | 25%ile | NVD | 2026-09-12 |
| CVE-2026-80071 | The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership | HIGH | 7.2 | 18%ile | NVD | 2026-09-13 |
| CVE-2026-83112 | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operati | HIGH | 7.2 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-83117 | Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-83176 | Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Frame | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-83195 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.2 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-83273 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-83298 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). The supported | HIGH | 7.2 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-83322 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-83325 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-83328 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-83344 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database Applicat | HIGH | 7.2 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-83440 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-83442 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-83453 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Interna | HIGH | 7.2 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-83481 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported ve | HIGH | 7.2 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-83482 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported ve | HIGH | 7.2 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-87207 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-87239 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-87244 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-87246 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.2 | 37%ile | NVD | 2026-09-15 |
| CVE-2026-85569 | The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to it | HIGH | 7.2 | 37%ile | NVD | 2026-09-16 |
| CVE-2026-82310 | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation | HIGH | 7.2 | 52%ile | NVD | 2026-09-16 |
| CVE-2026-81445 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerabilit | HIGH | 7.2 | 39%ile | NVD | 2026-09-17 |
| CVE-2026-81810 | The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of | HIGH | 7.2 | 4%ile | NVD | 2026-09-18 |
| CVE-2026-92619 | The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11 | HIGH | 7.2 | 31%ile | NVD | 2026-09-18 |
| CVE-2026-54369 | acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions | HIGH | 7.1 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-54371 | attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr | HIGH | 7.1 | 4%ile | Microsoft | 2026-06-09 |
| CVE-2026-83150 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to ex | HIGH | 7.0 | 1%ile | NVD | 2026-09-15 |
| CVE-2026-83239 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.0 | 1%ile | NVD | 2026-09-15 |
| CVE-2026-83316 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.0 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-87240 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.0 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-91097 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | HIGH | 7.0 | 50%ile | NVD | 2026-09-16 |
| CVE-2026-7006 | Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege | HIGH | 7.0 | — | NVD | 2026-09-18 |
| CVE-2026-63349 | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In | HIGH | 7.0 | — | NVD | 2026-09-18 |
| CVE-2025-3770 | SMM IDT Privilege Escalation Vulnerability | HIGH | 7.0 | 5%ile | Microsoft | 2025-08-12 |
| CVE-2026-2492 | TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability | HIGH | 7.0 | 17%ile | Microsoft | 2026-02-10 |
| CVE-2026-42016 | JFrog Artifactory Incorrect Authorization Vulnerability | HIGH | — | 58%ile | CISA-KEV | 2026-09-11 |
| CVE-2026-91100 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | MEDIUM | 6.8 | 16%ile | NVD | 2026-09-16 |
| CVE-2026-0179 | In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalat | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-87248 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | MEDIUM | 6.7 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-88922 | The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decomp | MEDIUM | 6.7 | 0%ile | NVD | 2026-09-15 |
| CVE-2026-26947 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privileg | MEDIUM | 6.7 | 6%ile | NVD | 2026-09-16 |
| CVE-2026-76694 | A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. | MEDIUM | 6.6 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-64753 | A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 2 | MEDIUM | 6.5 | 22%ile | NVD | 2026-09-14 |
| CVE-2026-1759 | Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escala | MEDIUM | 6.5 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-54168 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8 | MEDIUM | 6.5 | 35%ile | NVD | 2026-09-15 |
| CVE-2026-20287 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE | MEDIUM | 6.5 | 12%ile | NVD | 2026-09-16 |
| CVE-2026-89329 | A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this | MEDIUM | 6.2 | 2%ile | NVD | 2026-09-11 |
| CVE-2026-90523 | A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af0 | MEDIUM | 5.5 | 42%ile | NVD | 2026-09-13 |
| CVE-2026-90787 | A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is | MEDIUM | 5.5 | 34%ile | NVD | 2026-09-14 |
| CVE-2026-84587 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequo | MEDIUM | 5.5 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-84603 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27 | MEDIUM | 5.5 | 2%ile | NVD | 2026-09-14 |
| CVE-2026-86884 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golde | MEDIUM | 5.5 | 1%ile | NVD | 2026-09-14 |
| CVE-2026-90856 | A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts a | MEDIUM | 5.5 | 22%ile | NVD | 2026-09-15 |
| CVE-2026-88764 | The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal pay | MEDIUM | 5.4 | 4%ile | NVD | 2026-09-13 |
| CVE-2026-55226 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. I | MEDIUM | 5.4 | 8%ile | NVD | 2026-09-15 |
| CVE-2026-91099 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | MEDIUM | 5.1 | 26%ile | NVD | 2026-09-16 |
| CVE-2026-91101 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | MEDIUM | 5.1 | 21%ile | NVD | 2026-09-16 |
| CVE-2026-91103 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | MEDIUM | 5.1 | 21%ile | NVD | 2026-09-16 |
| CVE-2026-23791 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 26 | MEDIUM | 4.2 | 1%ile | NVD | 2026-09-14 |
| CVE-2026-90463 | A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending spec | MEDIUM | 4.0 | 1%ile | NVD | 2026-09-14 |
| CVE-2026-46696 | October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 hav | LOW | 3.3 | 12%ile | NVD | 2026-09-14 |
| CVE-2026-86893 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, vi | LOW | 3.3 | 1%ile | NVD | 2026-09-14 |
| CVE-2026-44778 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li | LOW | 2.9 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-90487 | A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the fi | LOW | 2.1 | 11%ile | NVD | 2026-09-12 |
| CVE-2026-90501 | A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.u | LOW | 2.1 | 10%ile | NVD | 2026-09-13 |
| CVE-2026-12003 | CPython >3.11 Insecure Input Validation resulting in privilege escalation | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |
| OSS-20260912-1 | Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKey | UNKNOWN | — | — | OSS-Security | 2026-09-12 |
| OSSN-0060 | OSSN-0060: = Glance configuration option can lead to privilege escalation = | UNKNOWN | — | — | OpenStack | 2026-08-27 |