VulnSea

CWE-269

CVEs classified under CWE-269, newest first.

470 CVEsRSS

CVE-2026-79744High· 8.8
3w ago

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT /api/system-config endpoint (handler u…

▾ TwilightEPSS 0.56%via NVD
CVE-2026-15369Critical· 9.8
4w ago

The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3

The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role val…

▾ MidnightEPSS 0.40%via NVD
CVE-2026-16259Critical· 9.8
4w ago

The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key …

The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key …

▾ MidnightEPSS 0.28%via NVD
CVE-2026-55843High· 6.5
1mo ago

Snipe-IT has an Improper Privilege Management issue

Snipe-IT has an Improper Privilege Management issue

▾ Twilightsnipe · snipe/snipe-itEPSS 0.54%via GHSA
CVE-2026-55485High· 8.8
1mo ago

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

▾ Twilightpiccolo-admin · piccolo-adminEPSS 0.56%via OSV
CVE-2026-79276Medium· 4.3
1mo ago

Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.28%via CVEORG
GHSA-pg62-f8g4-4wqhHigh· 8.8
1mo ago

phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold

phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold

▾ Twilightphpmyfaq · phpmyfaq/phpmyfaqvia GHSA
CVE-2026-53527High· 8.8
1mo ago

LeafWiki is a self-hosted wiki

LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate privileges from a regular user, such a…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-16937High· 7.8
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.

▾ TwilightEPSS 0.14%via NVD
CVE-2026-68561High· 8.8
1mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldName…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-16850High· 8.8
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection via crafted Router Advertisements.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection via crafted Router Advertisements.

▾ TwilightEPSS 1.5%via NVD
GHSA-m97h-2qj3-5773Critical· 9.1
1mo ago

Duplicate Advisory: Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin

Duplicate Advisory: Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin

▾ Midnightgetgrav · getgrav/gravvia GHSA
CVE-2026-73973Medium· 5.5
1mo ago

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-75845Medium· 6.3
1mo ago

ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool

ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool. SetServerSettingTool.execute() gates only on the global allowAdmin flag and never checks the caller's …

▾ SunlitEPSS 0.29%via NVD
CVE-2026-75837Critical· 9.1
1mo ago

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-ad…

▾ Midnightgetgrav · getgrav/gravEPSS 0.49%via NVD
CVE-2026-75857High· 7.0
1mo ago

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.15%via NVD
CVE-2026-71036Critical· 9.1
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allo…

▾ Midnightoracle · commerce_guided_searchEPSS 0.43%via NVD
CVE-2026-70928High· 8.8
1mo ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with n…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-73974Medium· 5.5
1mo ago

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linux…

▾ Sunlitlinuxfabrik-lib · linuxfabrik-libEPSS 0.17%via NVD
CVE-2026-75481High· 8.8PoC
1mo ago

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate it to administrator role, and authenticate with its…

▾ Midnightskypilot-org · skypilotEPSS 0.36%via NVD
CVE-2026-50774Critical· 9.8
1mo ago

An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.

An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.

▾ MidnightEPSS 0.61%via NVD
CVE-2026-45790High· 8.0
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission to invite a…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-18432Critical· 9.8
1mo ago

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit…

▾ MidnightEPSS 0.84%via NVD
CVE-2026-19928Medium· 6.3
1mo ago

A vulnerability was determined in OpenBoxes up to 0.9.7

A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can le…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-15142High· 7.5
1mo ago

The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6

The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat …

▾ TwilightEPSS 0.36%via NVD
CVE-2026-14279High· 8.8
1mo ago

The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request_send AJAX action

The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request_send AJAX action. The ced_wholesale_request_send_callback() handler only verifies a non…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-16772High· 8.1PoC
1mo ago

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` j…

▾ MidnightAkaunting · AkauntingEPSS 0.25%via NVD
CVE-2026-73664None
1mo ago

FreePBX is an open source IP PBX

FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/asterisk/.ssh/authorized_keys for the ast…

▾ SunlitEPSS 0.51%via NVD
CVE-2026-49819Critical· 9.8PoC
1mo ago

UpSnap is a wake on lan web app

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superu…

▾ Abyssalseriousm4x · UpSnapEPSS 1.1%via NVD
CVE-2026-73305High· 8.8
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleVali…

▾ TwilightEPSS 0.52%via NVD
CWE-269 vulnerabilities (CVEs) — page 11 · VulnSea