VulnSea

CWE-250

CVEs classified under CWE-250, newest first.

36 CVEsRSS

CVE-2026-92574High· 8.8
today

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities…

TwilightRed Hat · openshift-sandboxed-containers/osc-monitor-rhel9via NVD
CVE-2026-54501Critical· 9.4
4d ago

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Cust…

Midnightwebrecorder · browsertrixEPSS 1.2%via NVD
CVE-2026-75092High· 7.3
6d ago

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository)

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root…

TwilightRed Hat · leapp-repositoryEPSS 0.13%via NVD
CVE-2026-55225High· 8.0
6d ago

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator wat…

Twilightstrimzi · strimzi-kafka-operatorEPSS 0.19%via NVD
CVE-2026-89259Critical· 9.8
1w ago

Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS

Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --al…

Midnightgohugoio · hugoEPSS 0.41%via CVEORG
CVE-2026-79942Low· 3.4
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentiall…

Sunlitdell · secure_connect_gatewayEPSS 0.11%via NVD
CVE-2026-87506High· 8.3
1w ago

Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security…

Twilightgoogle · chromeEPSS 0.30%via NVD
CVE-2026-69464High· 8.8
1w ago

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.92%via NVD
CVE-2026-69409Medium· 6.5
1w ago

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sharepoint_serverEPSS 0.95%via NVD
CVE-2026-80238Critical· 9.3
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potential…

Midnightdell · secure_connect_gatewayEPSS 0.14%via NVD
CVE-2026-83534Medium· 6.4
2w ago

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and late…

SunlitDALIBO · PostgreSQL AnonymizerEPSS 0.19%via NVD
CVE-2026-30512High· 7.8
4w ago

A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5

A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to displa…

TwilightEPSS 0.13%via NVD
CVE-2026-76018High· 8.8
1mo ago

Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file

Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)

TwilightEPSS 0.39%via NVD
CVE-2026-71846Medium· 6.5
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive…

Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.12%via NVD
CVE-2026-17110High· 8.8
1mo ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.

Twilightibm · iEPSS 0.50%via NVD
CVE-2026-59133High· 8.8
1mo ago

Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.

Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · windows_appEPSS 0.94%via NVD
CVE-2026-18982High· 8.8
1mo ago

A flaw was found in the RHOAI training-operator

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can imperson…

TwilightRed Hat · rhoai/odh-training-operator-rhel9EPSS 0.53%via NVD
CVE-2026-18608High· 8.7
1mo ago

A flaw was found in the Data Science Pipelines Operator (DSPO)

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the…

TwilightRed Hat · rhoai/odh-data-science-pipelines-operator-controller-rhel9EPSS 0.47%via NVD
CVE-2026-48098High· 7.3
1mo ago

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using `sudo` and `shell=True` directly inside application logi…

TwilightEPSS 0.13%via NVD
CVE-2026-67609High· 7.8
1mo ago

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to the apache account to execute arbitrary commands as root by expl…

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to the apache account to execute arbitrary commands as root by expl…

TwilightEPSS 0.14%via NVD
CVE-2026-50565Medium· 4.9
2mo ago

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

Sunlitfission · github.com/fission/fissionEPSS 0.26%via GHSA
CVE-2026-50566Critical· 9.9
2mo ago

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

Midnightfission · github.com/fission/fissionEPSS 0.29%via GHSA
CVE-2026-48584Critical· 9.9
3mo ago

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

Midnightmicrosoft · azure_synapseEPSS 0.91%via NVD
CVE-2026-12505High· 7.8
3mo ago

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this…

TwilightEPSS 0.16%via NVD
CVE-2026-54319Medium· 4.2
3mo ago

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape

Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.24%via GHSA
CVE-2026-42890Medium
3mo ago

actual Allows Electron to Run As Node

actual Allows Electron to Run As Node

Sunlitactual · actualEPSS 0.13%via GHSA
CVE-2026-32673High· 8.7
4mo ago

A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges

A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments,…

TwilightEPSS 0.24%via NVD
CVE-2026-32643High· 8.7
4mo ago

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.  Note: Software vers…

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands.  Note: Software vers…

TwilightEPSS 0.16%via NVD
CVE-2026-4498High· 7.7
5mo ago

Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122)

Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index data beyond their direct Elasticsearch RBAC scope via Privilege Abuse (CAPEC-122). This requires an authenticated Kibana…

Twilightelastic · kibanaEPSS 0.30%via NVD
CVE-2026-1346Critical· 9.3
5mo ago

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a…

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a…

Midnightibm · security_verify_accessEPSS 0.23%via NVD
CWE-250 vulnerabilities (CVEs) · VulnSea