65 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-65884 | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provide | CRITICAL | 10.0 | 16%ile | NVD | 2026-07-29 |
| CVE-2026-48331 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv | CRITICAL | 10.0 | 38%ile | NVD | 2026-08-03 |
| CVE-2026-7374 | Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability | CRITICAL | 9.9 | 45%ile | Microsoft | 2026-05-12 |
| CVE-2026-14446 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the adminis | CRITICAL | 9.8 | 21%ile | NVD | 2026-07-28 |
| CVE-2026-13423 | The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauth | CRITICAL | 9.8 | 42%ile | NVD | 2026-07-29 |
| CVE-2026-48333 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege esca | CRITICAL | 9.8 | 38%ile | NVD | 2026-08-03 |
| CVE-2026-16534 | The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and | CRITICAL | 9.1 | 14%ile | NVD | 2026-08-03 |
| CVE-2026-18248 | @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.cont | CRITICAL | 9.1 | 12%ile | NVD | 2026-08-03 |
| CVE-2026-15992 | The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3. | HIGH | 8.8 | 20%ile | NVD | 2026-07-28 |
| CVE-2026-12144 | The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl | HIGH | 8.8 | 30%ile | NVD | 2026-07-29 |
| CVE-2026-5490 | DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privi | HIGH | 8.8 | 39%ile | NVD | 2026-07-29 |
| CVE-2026-17751 | Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ar | HIGH | 8.8 | 29%ile | NVD | 2026-07-30 |
| CVE-2026-17786 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who c | HIGH | 8.8 | 12%ile | NVD | 2026-07-30 |
| CVE-2026-17868 | Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform priv | HIGH | 8.8 | 26%ile | NVD | 2026-07-30 |
| CVE-2026-17899 | Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a | HIGH | 8.8 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-17950 | Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to | HIGH | 8.8 | 19%ile | NVD | 2026-07-30 |
| CVE-2026-17956 | Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute | HIGH | 8.8 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-17969 | Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute a | HIGH | 8.8 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-58222 | A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Do | HIGH | 8.8 | 54%ile | NVD | 2026-07-30 |
| CVE-2026-15414 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl | HIGH | 8.8 | 26%ile | NVD | 2026-08-01 |
| CVE-2026-16635 | The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 | HIGH | 8.8 | 23%ile | NVD | 2026-08-01 |
| CVE-2026-18650 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MY | HIGH | 8.8 | — | NVD | 2026-08-04 |
| CVE-2026-67356 | ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowin | HIGH | 8.7 | 16%ile | NVD | 2026-08-02 |
| CVE-2026-44093 | A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user t | HIGH | 8.5 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-44095 | A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to ex | HIGH | 8.5 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-44096 | A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, re | HIGH | 8.5 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-44099 | A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary | HIGH | 8.5 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-44106 | A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to exec | HIGH | 8.5 | 14%ile | NVD | 2026-07-30 |
| CVE-2026-67609 | Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalatio | HIGH | 8.5 | 4%ile | NVD | 2026-08-03 |
| CVE-2026-18759 | The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication | HIGH | 8.5 | 2%ile | NVD | 2026-08-04 |
| CVE-2026-17716 | Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege e | HIGH | 8.4 | 4%ile | NVD | 2026-07-30 |
| CVE-2026-17877 | Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to | HIGH | 8.4 | 1%ile | NVD | 2026-07-30 |
| CVE-2026-64634 | A vulnerability allowing local privilege escalation to the Reporter service context. | HIGH | 8.4 | — | NVD | 2026-08-04 |
| CVE-2026-14980 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which c | HIGH | 8.3 | 13%ile | NVD | 2026-07-30 |
| CVE-2026-48390 | Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker co | HIGH | 8.2 | 4%ile | NVD | 2026-07-28 |
| CVE-2026-12251 | The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it m | HIGH | 8.1 | 13%ile | NVD | 2026-07-31 |
| CVE-2026-54593 | Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions | HIGH | 8.1 | 28%ile | GitHub | 2026-07-28 |
| CVE-2026-18107 | A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insid | HIGH | 7.8 | 2%ile | NVD | 2026-07-28 |
| CVE-2026-13268 | G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows | HIGH | 7.8 | 5%ile | NVD | 2026-07-29 |
| CVE-2026-6102 | MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local | HIGH | 7.8 | 0%ile | NVD | 2026-07-29 |
| CVE-2026-17654 | Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege es | HIGH | 7.8 | 2%ile | NVD | 2026-07-30 |
| CVE-2026-17861 | Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker t | HIGH | 7.8 | 1%ile | NVD | 2026-07-30 |
| CVE-2026-17862 | Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-leve | HIGH | 7.8 | 2%ile | NVD | 2026-07-30 |
| CVE-2026-17863 | Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to p | HIGH | 7.8 | 1%ile | NVD | 2026-07-30 |
| CVE-2026-17864 | Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perfo | HIGH | 7.8 | 1%ile | NVD | 2026-07-30 |
| CVE-2026-12505 | Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2022-3650 | A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root | HIGH | 7.8 | 25%ile | Microsoft | 2023-01-10 |
| CVE-2023-22809 | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen | HIGH | 7.8 | 99%ile | Microsoft | 2023-01-10 |
| ionstack-2026 | IonStack Part 2: Linux kernel io_uring privilege escalation exploit chain | HIGH | 7.8 | — | Featured | 2026-07-07 |
| CVE-2026-17816 | Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker w | HIGH | 7.5 | 19%ile | NVD | 2026-07-30 |
| CVE-2026-17916 | Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co | HIGH | 7.5 | 6%ile | NVD | 2026-07-30 |
| CVE-2026-17930 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack | HIGH | 7.5 | 15%ile | NVD | 2026-07-30 |
| CVE-2026-17952 | Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to i | HIGH | 7.5 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-12687 | The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into th | HIGH | 7.5 | 22%ile | NVD | 2026-07-30 |
| CVE-2026-14333 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a p | HIGH | 7.5 | 22%ile | NVD | 2026-07-31 |
| CVE-2026-12080 | Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys | HIGH | 7.3 | 4%ile | Microsoft | 2026-07-14 |
| CVE-2026-17744 | Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to | HIGH | 7.1 | 10%ile | NVD | 2026-07-30 |
| CVE-2026-18606 | A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown function | HIGH | 7.1 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-17993 | Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalat | HIGH | 7.0 | 0%ile | NVD | 2026-07-30 |
| CVE-2026-17919 | Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to | MEDIUM | 6.8 | 2%ile | NVD | 2026-07-30 |
| CVE-2026-4878 | Libcap: libcap: privilege escalation via toctou race condition in cap_set_file() | MEDIUM | 6.7 | 11%ile | Microsoft | 2026-04-14 |
| CVE-2026-65835 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE | MEDIUM | 6.6 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-15430 | Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, | MEDIUM | 6.2 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-18477 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local a | MEDIUM | 4.4 | 1%ile | NVD | 2026-08-03 |
| CVE-2026-12003 | CPython >3.11 Insecure Input Validation resulting in privilege escalation | UNKNOWN | — | 4%ile | Microsoft | 2026-06-09 |