← Back to feed Search feed

CWE-269 Privilege Escalation vulnerabilities

65 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-65884Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provideCRITICAL10.016%ileNVD2026-07-29
CVE-2026-48331Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privCRITICAL10.038%ileNVD2026-08-03
CVE-2026-7374Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerabilityCRITICAL9.945%ileMicrosoft2026-05-12
CVE-2026-14446IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the adminisCRITICAL9.821%ileNVD2026-07-28
CVE-2026-13423The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthCRITICAL9.842%ileNVD2026-07-29
CVE-2026-48333Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escaCRITICAL9.838%ileNVD2026-08-03
CVE-2026-16534The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment andCRITICAL9.114%ileNVD2026-08-03
CVE-2026-18248@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.contCRITICAL9.112%ileNVD2026-08-03
CVE-2026-15992The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.HIGH8.820%ileNVD2026-07-28
CVE-2026-12144The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclHIGH8.830%ileNVD2026-07-29
CVE-2026-5490DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate priviHIGH8.839%ileNVD2026-07-29
CVE-2026-17751Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arHIGH8.829%ileNVD2026-07-30
CVE-2026-17786Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who cHIGH8.812%ileNVD2026-07-30
CVE-2026-17868Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privHIGH8.826%ileNVD2026-07-30
CVE-2026-17899Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a HIGH8.89%ileNVD2026-07-30
CVE-2026-17950Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker toHIGH8.819%ileNVD2026-07-30
CVE-2026-17956Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute HIGH8.821%ileNVD2026-07-30
CVE-2026-17969Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute aHIGH8.821%ileNVD2026-07-30
CVE-2026-58222A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory DoHIGH8.854%ileNVD2026-07-30
CVE-2026-15414The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and inclHIGH8.826%ileNVD2026-08-01
CVE-2026-16635The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0HIGH8.823%ileNVD2026-08-01
CVE-2026-18650Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYHIGH8.8NVD2026-08-04
CVE-2026-67356ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowinHIGH8.716%ileNVD2026-08-02
CVE-2026-44093A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user tHIGH8.514%ileNVD2026-07-30
CVE-2026-44095A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to exHIGH8.514%ileNVD2026-07-30
CVE-2026-44096A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, reHIGH8.514%ileNVD2026-07-30
CVE-2026-44099A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitraryHIGH8.514%ileNVD2026-07-30
CVE-2026-44106A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execHIGH8.514%ileNVD2026-07-30
CVE-2026-67609Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalatioHIGH8.54%ileNVD2026-08-03
CVE-2026-18759The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communicationHIGH8.52%ileNVD2026-08-04
CVE-2026-17716Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege eHIGH8.44%ileNVD2026-07-30
CVE-2026-17877Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to HIGH8.41%ileNVD2026-07-30
CVE-2026-64634A vulnerability allowing local privilege escalation to the Reporter service context.HIGH8.4NVD2026-08-04
CVE-2026-14980IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which cHIGH8.313%ileNVD2026-07-30
CVE-2026-48390Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker coHIGH8.24%ileNVD2026-07-28
CVE-2026-12251The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it mHIGH8.113%ileNVD2026-07-31
CVE-2026-54593Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissionsHIGH8.128%ileGitHub2026-07-28
CVE-2026-18107A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insidHIGH7.82%ileNVD2026-07-28
CVE-2026-13268G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows HIGH7.85%ileNVD2026-07-29
CVE-2026-6102MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows localHIGH7.80%ileNVD2026-07-29
CVE-2026-17654Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege esHIGH7.82%ileNVD2026-07-30
CVE-2026-17861Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker tHIGH7.81%ileNVD2026-07-30
CVE-2026-17862Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-leveHIGH7.82%ileNVD2026-07-30
CVE-2026-17863Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to pHIGH7.81%ileNVD2026-07-30
CVE-2026-17864Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perfoHIGH7.81%ileNVD2026-07-30
CVE-2026-12505Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcallHIGH7.85%ileMicrosoft2026-06-09
CVE-2022-3650A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to rootHIGH7.825%ileMicrosoft2023-01-10
CVE-2023-22809In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmenHIGH7.899%ileMicrosoft2023-01-10
ionstack-2026IonStack Part 2: Linux kernel io_uring privilege escalation exploit chainHIGH7.8Featured2026-07-07
CVE-2026-17816Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker wHIGH7.519%ileNVD2026-07-30
CVE-2026-17916Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had coHIGH7.56%ileNVD2026-07-30
CVE-2026-17930Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attackHIGH7.515%ileNVD2026-07-30
CVE-2026-17952Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to iHIGH7.59%ileNVD2026-07-30
CVE-2026-12687The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into thHIGH7.522%ileNVD2026-07-30
CVE-2026-14333The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a pHIGH7.522%ileNVD2026-07-31
CVE-2026-12080Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keysHIGH7.34%ileMicrosoft2026-07-14
CVE-2026-17744Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker toHIGH7.110%ileNVD2026-07-30
CVE-2026-18606A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionHIGH7.12%ileNVD2026-08-03
CVE-2026-17993Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalatHIGH7.00%ileNVD2026-07-30
CVE-2026-17919Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker toMEDIUM6.82%ileNVD2026-07-30
CVE-2026-4878Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()MEDIUM6.711%ileMicrosoft2026-04-14
CVE-2026-65835Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVEMEDIUM6.69%ileNVD2026-07-30
CVE-2026-15430Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, MEDIUM6.21%ileNVD2026-08-03
CVE-2026-18477A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local aMEDIUM4.41%ileNVD2026-08-03
CVE-2026-12003CPython >3.11 Insecure Input Validation resulting in privilege escalationUNKNOWN4%ileMicrosoft2026-06-09