VulnSea

CWE-269

CVEs classified under CWE-269, newest first.

470 CVEsRSS

CVE-2026-13756High· 8.8
2mo ago

The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3

The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/…

▾ TwilightEPSS 0.44%via NVD
CVE-2026-44787High· 8.2
2mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and gain whisper-group privileges without legitimate group m…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-0276None
2mo ago

A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.

A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.

▾ SunlitEPSS 0.14%via NVD
CVE-2026-50201Medium· 6.5
2mo ago

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

▾ SunlitSteeltoe · Steeltoe.Management.EndpointEPSS 0.40%via GHSA
GHSA-rggc-m335-3wvjHigh
2mo ago

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-46680High· 7.8PoC
2mo ago

containerd is an open-source container runtime

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leadi…

▾ Midnightlinuxfoundation · containerdEPSS 0.16%via NVD
GHSA-7m8x-qg2j-4m3vHigh· 8.1
2mo ago

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

▾ Twilightfission · github.com/fission/fissionvia GHSA
CVE-2026-50545Critical· 9.9
2mo ago

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

▾ Midnightfission · github.com/fission/fissionEPSS 0.52%via GHSA
CVE-2026-50563Critical· 9.9
2mo ago

Fission Container Executor Function PodSpec Injection Leading to Node Escape

Fission Container Executor Function PodSpec Injection Leading to Node Escape

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-50564Critical· 9.9
2mo ago

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-50565Medium· 4.9
2mo ago

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container

▾ Sunlitfission · github.com/fission/fissionEPSS 0.44%via GHSA
CVE-2026-50566Critical· 9.9
2mo ago

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-52808High· 7.1
3mo ago

Gogs's write-level collaborators can mutate admin-only repository settings via API

Gogs's write-level collaborators can mutate admin-only repository settings via API

▾ Twilightgogs · gogs.io/gogsEPSS 0.48%via GHSA
GHSA-qxvg-h7q2-hcxhCritical· 9.8
3mo ago

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

▾ Midnightmotioneye · motioneyevia GHSA
CVE-2026-54099High· 8.8
3mo ago

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not rej…

▾ Twilightredhat · openshift_container_platformEPSS 0.11%via NVD
CVE-2026-54319Medium· 4.2
3mo ago

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape

▾ Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.24%via GHSA
CVE-2026-53855High· 8.1
3mo ago

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-53862Low· 4.2
3mo ago

OpenClaw: Bootstrap token replay could widen pending pairing scopes

OpenClaw: Bootstrap token replay could widen pending pairing scopes

▾ Sunlitopenclaw · openclawEPSS 0.13%via GHSA
CVE-2026-54415High· 8.1PoC
3mo ago

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…

▾ MidnightEPSS 0.49%via NVD
CVE-2026-12289High· 8.8
3mo ago

Privilege escalation in the Graphics: WebRender component

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

▾ Twilightmozilla · firefoxEPSS 0.40%via NVD
CVE-2026-47725High
3mo ago

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.22%via GHSA
CVE-2026-0009High· 7.8PoC
3mo ago

In multiple locations, there is a possible tapjacking due to a logic error in the code

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Midnightgoogle · androidEPSS 0.09%via NVD
CVE-2026-0091High· 7.8PoC
3mo ago

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

▾ Midnightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0089High· 7.8
3mo ago

In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check

In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed.…

▾ Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-0086Medium· 6.8
3mo ago

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interacti…

▾ Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-45632Critical· 9.9
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete schedules belongi…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-46817Critical· 9.8CISA KEVPoC
4mo ago

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission)

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with netwo…

▾ Hadaloracle · e-business_suiteEPSS 0.81%via NVD
CVE-2026-23663High· 7.5
4mo ago

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · global_secure_accessEPSS 0.55%via NVD
CVE-2026-9018High· 8.8PoC
4mo ago

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_…

▾ MidnightEPSS 0.59%via NVD
CVE-2026-8972High· 8.8
4mo ago

Privilege escalation in the WebRTC: Audio/Video component

Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

▾ Twilightmozilla · firefoxEPSS 0.44%via NVD
CWE-269 vulnerabilities (CVEs) — page 14 · VulnSea