← Back to feed Search feed

CWE-269 Privilege Escalation vulnerabilities

276 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-76669Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful explCRITICAL9.938%ileNVD2026-09-15
CVE-2026-76670Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful explCRITICAL9.938%ileNVD2026-09-15
CVE-2026-83282Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeCRITICAL9.921%ileNVD2026-09-15
CVE-2026-87172Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.924%ileNVD2026-09-15
CVE-2026-7374Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerabilityCRITICAL9.953%ileMicrosoft2026-05-12
CVE-2026-89610In the Linux kernel, the following vulnerability has been resolved: ntfs: verify run length exceeding volume boundary CRITICAL9.845%ileNVD2026-09-11
CVE-2026-85681The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it maCRITICAL9.820%ileNVD2026-09-12
CVE-2026-73470Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles notCRITICAL9.840%ileNVD2026-09-14
CVE-2026-12793The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versiCRITICAL9.833%ileNVD2026-09-16
CVE-2026-87186Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.69%ileNVD2026-09-15
CVE-2026-21391An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID CRITICAL9.538%ileNVD2026-09-14
CVE-2026-92957vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) CRITICAL9.441%ileNVD2026-09-17
CVE-2026-91104HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several CRITICAL9.352%ileNVD2026-09-16
CVE-2026-91106HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several CRITICAL9.350%ileNVD2026-09-16
CVE-2026-24834Kata Container to Guest micro VM privilege escalationCRITICAL9.313%ileMicrosoft2026-02-10
CVE-2026-83196Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vCRITICAL9.128%ileNVD2026-09-15
CVE-2026-83260Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Event Java PX). The supported versionCRITICAL9.139%ileNVD2026-09-15
CVE-2026-83268Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiCRITICAL9.128%ileNVD2026-09-15
CVE-2026-87189Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.139%ileNVD2026-09-15
CVE-2026-87214Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.125%ileNVD2026-09-15
CVE-2026-61549Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_opCRITICAL9.06%ileNVD2026-09-15
CVE-2026-62102Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.HIGH8.825%ileNVD2026-09-11
CVE-2026-62106Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.HIGH8.825%ileNVD2026-09-11
CVE-2026-87759The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pHIGH8.814%ileNVD2026-09-12
CVE-2026-15451The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incHIGH8.816%ileNVD2026-09-12
CVE-2026-14805The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This HIGH8.824%ileNVD2026-09-15
CVE-2026-92006Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.829%ileNVD2026-09-15
CVE-2026-92007Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%ileNVD2026-09-15
CVE-2026-92008Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%ileNVD2026-09-15
CVE-2026-92009Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%ileNVD2026-09-15
CVE-2026-92010Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%ileNVD2026-09-15
CVE-2026-92011Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%ileNVD2026-09-15
CVE-2026-92012Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%ileNVD2026-09-15
CVE-2026-92013Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%ileNVD2026-09-15
CVE-2026-92014Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in FirHIGH8.817%ileNVD2026-09-15
CVE-2026-92015Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, FiHIGH8.820%ileNVD2026-09-15
CVE-2026-92017Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115HIGH8.817%ileNVD2026-09-15
CVE-2026-92020Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fHIGH8.820%ileNVD2026-09-15
CVE-2026-92033Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.HIGH8.811%ileNVD2026-09-15
CVE-2026-92043Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in HIGH8.817%ileNVD2026-09-15
CVE-2026-92047Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, THIGH8.815%ileNVD2026-09-15
CVE-2026-92052Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed inHIGH8.817%ileNVD2026-09-15
CVE-2026-92053Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 15HIGH8.818%ileNVD2026-09-15
CVE-2026-92054Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunderbirHIGH8.818%ileNVD2026-09-15
CVE-2026-92055Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunderbHIGH8.816%ileNVD2026-09-15
CVE-2026-92062Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, THIGH8.815%ileNVD2026-09-15
CVE-2026-92073Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.HIGH8.815%ileNVD2026-09-15
CVE-2026-16140OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an eHIGH8.820%ileNVD2026-09-15
CVE-2026-40058CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability onHIGH8.80%ileNVD2026-09-15
CVE-2026-79411Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated baHIGH8.824%ileNVD2026-09-15
CVE-2026-76677A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allHIGH8.836%ileNVD2026-09-15
CVE-2026-83119Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Internal Operations). SupporHIGH8.833%ileNVD2026-09-15
CVE-2026-83120Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versioHIGH8.833%ileNVD2026-09-15
CVE-2026-83121Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions thatHIGH8.833%ileNVD2026-09-15
CVE-2026-83148Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitaHIGH8.836%ileNVD2026-09-15
CVE-2026-83168Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics InterHIGH8.833%ileNVD2026-09-15
CVE-2026-83189Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). SuppHIGH8.833%ileNVD2026-09-15
CVE-2026-83194Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). SupportedHIGH8.836%ileNVD2026-09-15
CVE-2026-83212Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported HIGH8.824%ileNVD2026-09-15
CVE-2026-83271Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21HIGH8.836%ileNVD2026-09-15
CVE-2026-83301Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Service AdmHIGH8.833%ileNVD2026-09-15
CVE-2026-83306Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). SuppHIGH8.836%ileNVD2026-09-15
CVE-2026-83315Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiHIGH8.836%ileNVD2026-09-15
CVE-2026-83329Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). SupHIGH8.833%ileNVD2026-09-15
CVE-2026-83331Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). SupHIGH8.833%ileNVD2026-09-15
CVE-2026-83335Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics SHIGH8.833%ileNVD2026-09-15
CVE-2026-83338Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics InterHIGH8.833%ileNVD2026-09-15
CVE-2026-83340Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versiHIGH8.833%ileNVD2026-09-15
CVE-2026-83348Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21HIGH8.836%ileNVD2026-09-15
CVE-2026-83410Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that arHIGH8.824%ileNVD2026-09-15
CVE-2026-83411Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that arHIGH8.821%ileNVD2026-09-15
CVE-2026-83423Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported vHIGH8.821%ileNVD2026-09-15
CVE-2026-83444Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH8.824%ileNVD2026-09-15
CVE-2026-83445Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: InteHIGH8.824%ileNVD2026-09-15
CVE-2026-83454Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: InternaHIGH8.836%ileNVD2026-09-15
CVE-2026-83456Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations)HIGH8.836%ileNVD2026-09-15
CVE-2026-83479Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported veHIGH8.824%ileNVD2026-09-15
CVE-2026-87150Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). SupporteHIGH8.836%ileNVD2026-09-15
CVE-2026-87155Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH8.836%ileNVD2026-09-15
CVE-2026-87162Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componenHIGH8.824%ileNVD2026-09-15
CVE-2026-87163Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions HIGH8.836%ileNVD2026-09-15
CVE-2026-87165Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componenHIGH8.824%ileNVD2026-09-15
CVE-2026-87179Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.836%ileNVD2026-09-15
CVE-2026-87180Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.836%ileNVD2026-09-15
CVE-2026-87181Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.824%ileNVD2026-09-15
CVE-2026-87182Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.82%ileNVD2026-09-15
CVE-2026-87185Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.824%ileNVD2026-09-15
CVE-2026-87187Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.811%ileNVD2026-09-15
CVE-2026-87201Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.821%ileNVD2026-09-15
CVE-2026-87202Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.821%ileNVD2026-09-15
CVE-2026-87204Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.833%ileNVD2026-09-15
CVE-2026-87224Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.833%ileNVD2026-09-15
CVE-2026-87226Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.821%ileNVD2026-09-15
CVE-2026-87227Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.833%ileNVD2026-09-15
CVE-2026-87238Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.825%ileNVD2026-09-15
CVE-2026-88904The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests theHIGH8.814%ileNVD2026-09-17
CVE-2026-12954The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and includingHIGH8.839%ileNVD2026-09-18
CVE-2026-55887MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YHIGH8.710%ileNVD2026-09-15
CVE-2026-88817An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an exiHIGH8.720%ileNVD2026-09-16
CVE-2026-87273Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH8.62%ileNVD2026-09-15
CVE-2026-92716Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint thaHIGH8.624%ileNVD2026-09-16
CVE-2026-91098HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several HIGH8.650%ileNVD2026-09-16
CVE-2026-91105HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several HIGH8.650%ileNVD2026-09-16
CVE-2026-90493A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is HIGH8.51%ileNVD2026-09-13
CVE-2026-12518A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileHIGH8.51%ileNVD2026-09-14
CVE-2026-83272Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 19.3-19.HIGH8.526%ileNVD2026-09-15
CVE-2026-83451Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.517%ileNVD2026-09-15
CVE-2026-91102HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several HIGH8.416%ileNVD2026-09-16
CVE-2026-92958vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard togeHIGH8.420%ileNVD2026-09-17
CVE-2026-65354A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS GoldeHIGH8.23%ileNVD2026-09-14
CVE-2026-83169Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues). HIGH8.131%ileNVD2026-09-15
CVE-2026-83191Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH8.131%ileNVD2026-09-15
CVE-2026-83192Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that areHIGH8.122%ileNVD2026-09-15
CVE-2026-83245Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.122%ileNVD2026-09-15
CVE-2026-83246Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.122%ileNVD2026-09-15
CVE-2026-83254Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.122%ileNVD2026-09-15
CVE-2026-83255Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.122%ileNVD2026-09-15
CVE-2026-83256Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.131%ileNVD2026-09-15
CVE-2026-83258Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.122%ileNVD2026-09-15
CVE-2026-83286Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH8.128%ileNVD2026-09-15
CVE-2026-83299Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics WHIGH8.128%ileNVD2026-09-15
CVE-2026-83351Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3HIGH8.122%ileNVD2026-09-15
CVE-2026-83464Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal ServerHIGH8.122%ileNVD2026-09-15
CVE-2026-87231Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.128%ileNVD2026-09-15
CVE-2026-85530The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value HIGH8.130%ileNVD2026-09-16
CVE-2026-81442Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerabilitHIGH8.132%ileNVD2026-09-17
CVE-2026-56668ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token ExchangeHIGH8.135%ileGitHub2026-09-14
CVE-2026-54330Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalationHIGH8.18%ileMicrosoft2026-08-11
CVE-2026-55225Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. IHIGH8.09%ileNVD2026-09-15
CVE-2026-83170Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). SupportedHIGH8.018%ileNVD2026-09-15
CVE-2026-83450Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). SupporteHIGH8.030%ileNVD2026-09-15
CVE-2026-83483Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis)HIGH8.030%ileNVD2026-09-15
CVE-2026-87164Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). SuppHIGH8.012%ileNVD2026-09-15
CVE-2026-87245Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.011%ileNVD2026-09-15
CVE-2026-89579In the Linux kernel, the following vulnerability has been resolved: bpf: Harden bloom filter sizing and indexing on 32-HIGH7.86%ileNVD2026-09-11
CVE-2026-90894Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_sHIGH7.84%ileNVD2026-09-14
CVE-2026-19624A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vHIGH7.83%ileNVD2026-09-14
CVE-2026-92180pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation VulHIGH7.84%ileNVD2026-09-15
CVE-2026-83118Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions HIGH7.84%ileNVD2026-09-15
CVE-2026-83147Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). THIGH7.84%ileNVD2026-09-15
CVE-2026-83211Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.84%ileNVD2026-09-15
CVE-2026-83214Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.82%ileNVD2026-09-15
CVE-2026-83216Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.82%ileNVD2026-09-15
CVE-2026-83247Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.86%ileNVD2026-09-15
CVE-2026-83249Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.81%ileNVD2026-09-15
CVE-2026-83253Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.83%ileNVD2026-09-15
CVE-2026-83288Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search).HIGH7.84%ileNVD2026-09-15
CVE-2026-83290Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.84%ileNVD2026-09-15
CVE-2026-83291Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.84%ileNVD2026-09-15
CVE-2026-83293Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: FNDN). ThHIGH7.84%ileNVD2026-09-15
CVE-2026-83294Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.86%ileNVD2026-09-15
CVE-2026-83317Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: InstallatioHIGH7.84%ileNVD2026-09-15
CVE-2026-83336Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics SHIGH7.84%ileNVD2026-09-15
CVE-2026-83337Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: RemoteHIGH7.84%ileNVD2026-09-15
CVE-2026-83342Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: SysHIGH7.82%ileNVD2026-09-15
CVE-2026-83353Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). SupporteHIGH7.82%ileNVD2026-09-15
CVE-2026-83420Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering).HIGH7.84%ileNVD2026-09-15
CVE-2026-87216Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.83%ileNVD2026-09-15
CVE-2026-87268Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.84%ileNVD2026-09-15
CVE-2026-87269Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.82%ileNVD2026-09-15
CVE-2026-87270Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.82%ileNVD2026-09-15
CVE-2026-87271Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.84%ileNVD2026-09-15
CVE-2026-87272Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.84%ileNVD2026-09-15
CVE-2026-89791In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when perf mmap() revival rHIGH7.84%ileNVD2026-09-16
CVE-2026-90046In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP PHIGH7.84%ileNVD2026-09-16
CVE-2026-87886Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin HIGH7.821%ileNVD2026-09-17
CVE-2026-46655virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permitsHIGH7.8NVD2026-09-18
CVE-2026-72693Kbd: local privilege escalation in openvt via incorrect process owner verification allowing passwordless root loginHIGH7.81%ileMicrosoft2026-08-11
CVE-2026-12505Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcallHIGH7.85%ileMicrosoft2026-06-09
CVE-2026-76642util-linux libmount Privilege Escalation via Failed Mount HelperHIGH7.87%ileMicrosoft2026-09-08
ionstack-2026IonStack Part 2: Linux kernel io_uring privilege escalation exploit chainHIGH7.8Featured2026-07-07
CVE-2026-65831ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with langHIGH7.738%ileNVD2026-09-15
CVE-2026-87183Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.75%ileNVD2026-09-15
CVE-2026-54087EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFieHIGH7.623%ileNVD2026-09-14
CVE-2026-54175backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaHIGH7.632%ileNVD2026-09-14
CVE-2026-92616FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attHIGH7.626%ileNVD2026-09-16
CVE-2026-86406The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a memHIGH7.59%ileNVD2026-09-13
CVE-2026-75983The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to PrivileHIGH7.535%ileNVD2026-09-15
CVE-2026-83114Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versHIGH7.523%ileNVD2026-09-15
CVE-2026-83241Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.524%ileNVD2026-09-15
CVE-2026-83257Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.517%ileNVD2026-09-15
CVE-2026-83262Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).HIGH7.526%ileNVD2026-09-15
CVE-2026-83263Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).HIGH7.517%ileNVD2026-09-15
CVE-2026-83289Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics WHIGH7.526%ileNVD2026-09-15
CVE-2026-83292Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.523%ileNVD2026-09-15
CVE-2026-83295Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: PresentatioHIGH7.526%ileNVD2026-09-15
CVE-2026-83296Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search).HIGH7.523%ileNVD2026-09-15
CVE-2026-83318Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions thHIGH7.526%ileNVD2026-09-15
CVE-2026-83323Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.51%ileNVD2026-09-15
CVE-2026-83415Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that arHIGH7.523%ileNVD2026-09-15
CVE-2026-83463Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal ServerHIGH7.515%ileNVD2026-09-15
CVE-2026-83489Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: OnboardingHIGH7.526%ileNVD2026-09-15
CVE-2026-87139Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.517%ileNVD2026-09-15
CVE-2026-87140Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.526%ileNVD2026-09-15
CVE-2026-87190Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.526%ileNVD2026-09-15
CVE-2026-87203Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.523%ileNVD2026-09-15
CVE-2026-87237Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.523%ileNVD2026-09-15
CVE-2026-87247Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.515%ileNVD2026-09-15
CVE-2026-85128The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration HIGH7.58%ileNVD2026-09-17
CVE-2026-50605A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. InsuHIGH7.41%ileNVD2026-09-17
CVE-2026-50609A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. HIGH7.41%ileNVD2026-09-17
CVE-2026-50610A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense dHIGH7.41%ileNVD2026-09-17
CVE-2026-75092A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository).HIGH7.33%ileNVD2026-09-15
CVE-2026-83190Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.34%ileNVD2026-09-15
CVE-2026-83193Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: Life Sciences). Supported verHIGH7.34%ileNVD2026-09-15
CVE-2026-12080Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keysHIGH7.38%ileMicrosoft2026-07-14
CVE-2026-77752The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary HIGH7.225%ileNVD2026-09-12
CVE-2026-80071The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membershipHIGH7.218%ileNVD2026-09-13
CVE-2026-83112Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal OperatiHIGH7.239%ileNVD2026-09-15
CVE-2026-83117Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions HIGH7.237%ileNVD2026-09-15
CVE-2026-83176Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management FrameHIGH7.237%ileNVD2026-09-15
CVE-2026-83195Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.239%ileNVD2026-09-15
CVE-2026-83273Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.237%ileNVD2026-09-15
CVE-2026-83298Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). The supported HIGH7.239%ileNVD2026-09-15
CVE-2026-83322Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.237%ileNVD2026-09-15
CVE-2026-83325Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.237%ileNVD2026-09-15
CVE-2026-83328Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). SupHIGH7.237%ileNVD2026-09-15
CVE-2026-83344Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database ApplicatHIGH7.239%ileNVD2026-09-15
CVE-2026-83440Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH7.237%ileNVD2026-09-15
CVE-2026-83442Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH7.237%ileNVD2026-09-15
CVE-2026-83453Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: InternaHIGH7.228%ileNVD2026-09-15
CVE-2026-83481Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported veHIGH7.228%ileNVD2026-09-15
CVE-2026-83482Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported veHIGH7.228%ileNVD2026-09-15
CVE-2026-87207Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.237%ileNVD2026-09-15
CVE-2026-87239Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.237%ileNVD2026-09-15
CVE-2026-87244Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.237%ileNVD2026-09-15
CVE-2026-87246Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.237%ileNVD2026-09-15
CVE-2026-85569The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to itHIGH7.237%ileNVD2026-09-16
CVE-2026-82310Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivationHIGH7.252%ileNVD2026-09-16
CVE-2026-81445Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerabilitHIGH7.239%ileNVD2026-09-17
CVE-2026-81810The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several ofHIGH7.24%ileNVD2026-09-18
CVE-2026-92619The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11HIGH7.231%ileNVD2026-09-18
CVE-2026-54369acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl FunctionsHIGH7.15%ileMicrosoft2026-06-09
CVE-2026-54371attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattrHIGH7.14%ileMicrosoft2026-06-09
CVE-2026-83150Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exHIGH7.01%ileNVD2026-09-15
CVE-2026-83239Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.01%ileNVD2026-09-15
CVE-2026-83316Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.02%ileNVD2026-09-15
CVE-2026-87240Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.00%ileNVD2026-09-15
CVE-2026-91097HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several HIGH7.050%ileNVD2026-09-16
CVE-2026-7006Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege HIGH7.0NVD2026-09-18
CVE-2026-63349AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In HIGH7.0NVD2026-09-18
CVE-2025-3770SMM IDT Privilege Escalation VulnerabilityHIGH7.05%ileMicrosoft2025-08-12
CVE-2026-2492TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityHIGH7.017%ileMicrosoft2026-02-10
CVE-2026-42016JFrog Artifactory Incorrect Authorization VulnerabilityHIGH58%ileCISA-KEV2026-09-11
CVE-2026-91100HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several MEDIUM6.816%ileNVD2026-09-16
CVE-2026-0179In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalatMEDIUM6.70%ileNVD2026-09-15
CVE-2026-87248Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporMEDIUM6.74%ileNVD2026-09-15
CVE-2026-88922The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompMEDIUM6.70%ileNVD2026-09-15
CVE-2026-26947Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper PrivilegMEDIUM6.76%ileNVD2026-09-16
CVE-2026-76694A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways.MEDIUM6.636%ileNVD2026-09-15
CVE-2026-64753A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 2MEDIUM6.522%ileNVD2026-09-14
CVE-2026-1759Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege EscalaMEDIUM6.518%ileNVD2026-09-15
CVE-2026-54168Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8MEDIUM6.535%ileNVD2026-09-15
CVE-2026-20287As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISEMEDIUM6.512%ileNVD2026-09-16
CVE-2026-89329A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this MEDIUM6.22%ileNVD2026-09-11
CVE-2026-90523A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af0MEDIUM5.542%ileNVD2026-09-13
CVE-2026-90787A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is MEDIUM5.534%ileNVD2026-09-14
CVE-2026-84587A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS SequoMEDIUM5.52%ileNVD2026-09-14
CVE-2026-84603A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27MEDIUM5.52%ileNVD2026-09-14
CVE-2026-86884A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS GoldeMEDIUM5.51%ileNVD2026-09-14
CVE-2026-90856A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts aMEDIUM5.522%ileNVD2026-09-15
CVE-2026-88764The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payMEDIUM5.44%ileNVD2026-09-13
CVE-2026-55226Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. IMEDIUM5.48%ileNVD2026-09-15
CVE-2026-91099HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several MEDIUM5.126%ileNVD2026-09-16
CVE-2026-91101HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several MEDIUM5.121%ileNVD2026-09-16
CVE-2026-91103HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several MEDIUM5.121%ileNVD2026-09-16
CVE-2026-23791An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 26MEDIUM4.21%ileNVD2026-09-14
CVE-2026-90463A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specMEDIUM4.01%ileNVD2026-09-14
CVE-2026-46696October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 havLOW3.312%ileNVD2026-09-14
CVE-2026-86893A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, viLOW3.31%ileNVD2026-09-14
CVE-2026-44778Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and LiLOW2.939%ileNVD2026-09-15
CVE-2026-90487A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the fiLOW2.111%ileNVD2026-09-12
CVE-2026-90501A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.uLOW2.110%ileNVD2026-09-13
CVE-2026-12003CPython >3.11 Insecure Input Validation resulting in privilege escalationUNKNOWN4%ileMicrosoft2026-06-09
OSS-20260912-1Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKeyUNKNOWNOSS-Security2026-09-12
OSSN-0060OSSN-0060: = Glance configuration option can lead to privilege escalation =UNKNOWNOpenStack2026-08-27