VulnSea

CWE-269

CVEs classified under CWE-269, newest first.

470 CVEsRSS

CVE-2026-8970High· 8.8
4mo ago

Privilege escalation in the Security component

Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

▾ Twilightmozilla · firefoxEPSS 0.41%via NVD
CVE-2026-46333High· 7.1PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can c…

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can c…

▾ Midnightlinux · linux_kernelEPSS 0.51%via NVD
CVE-2026-28995High· 8.8PoC
4mo ago

A logic issue was addressed with improved restrictions

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A…

▾ Midnightapple · ipadosEPSS 0.15%via NVD
CVE-2026-8069High· 7.8PoC
4mo ago

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions

PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigu…

▾ Midnightacer · nitrosenseEPSS 0.17%via NVD
CVE-2026-40002Medium· 5.0
5mo ago

Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations

Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications accessing the service interface. Exploiting …

▾ Sunlitzte · nubia-in_nx809j_firmwareEPSS 0.15%via NVD
CVE-2026-32181Medium· 5.5
5mo ago

Connected User Experiences and Telemetry Service Denial of Service Vulnerability

Improper privilege management in Microsoft Windows allows an authorized attacker to deny service locally.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.42%via CVEORG
CVE-2026-32212Medium· 5.5
5mo ago

Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.37%via CVEORG
CVE-2026-27456Medium· 4.7
5mo ago

util-linux is a random collection of Linux utilities

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up lo…

▾ Sunlitkernel · util-linuxEPSS 0.12%via NVD
CVE-2026-34218Medium· 5.5
6mo ago

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup defects created a window during which only the single compile-time baseline rule was enforc…

▾ Sunlitcraigjbass · clearancekitEPSS 0.15%via NVD
CVE-2026-2640Medium· 5.5
6mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes.

▾ Sunlitlenovo · pcmanagerEPSS 0.12%via NVD
CVE-2026-20044Medium· 6.0
6mo ago

A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrict…

A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrict…

▾ Sunlitcisco · secure_firewall_management_centerEPSS 0.14%via NVD
CVE-2026-26369High· 8.8
7mo ago

eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method

eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrp…

▾ Twilightjung-group · enet_smart_homeEPSS 0.52%via NVD
CVE-2025-59705Medium· 6.8
9mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis pro…

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to Escalate Privileges by enabling the USB interface through chassis pro…

▾ Sunlitentrust · nshield_5c_firmwareEPSS 0.33%via NVD
CVE-2025-59697High· 7.2
9mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configurati…

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configurati…

▾ Twilightentrust · nshield_5c_firmwareEPSS 0.31%via NVD
CVE-2025-59693Critical· 9.8
9mo ago

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate pri…

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate pri…

▾ Midnightentrust · nshield_5c_firmwareEPSS 0.90%via NVD
CVE-2025-13787Medium· 5.4
10mo ago

A flaw has been found in ZenTao up to 21.7.6-8564

A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper pr…

▾ Sunlitzentao · zentaoEPSS 0.38%via NVD
CVE-2025-54821Low· 1.9
10mo ago

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, F…

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.6.0, F…

▾ Sunlitfortinet · fortiproxyEPSS 0.15%via NVD
CVE-2024-13997High· 7.2
10mo ago

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the mig…

▾ Twilightnagios · nagios_xiEPSS 1.1%via NVD
CVE-2025-11561High· 8.8
11mo ago

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a f…

▾ TwilightEPSS 0.80%via NVD
CVE-2025-4334Critical· 9.8PoC
1y ago

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. Thi…

▾ Abyssalnajeebmedia · memberheroEPSS 2.3%via NVD
CVE-2024-11218High· 8.6
1y ago

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it …

▾ Twilightcontainers · github.com/containers/buildahEPSS 0.36%via NVD
CVE-2024-52336High· 7.8
1y ago

A script injection vulnerability was identified in the Tuned package

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus…

▾ TwilightEPSS 0.29%via NVD
CVE-2024-8424None
1y ago

Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions.

Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions.

▾ SunlitEPSS 0.19%via NVD
CVE-2024-45496Critical· 9.9
2y ago

A flaw was found in OpenShift

A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged securit…

▾ MidnightEPSS 1.0%via NVD
CVE-2024-33775High· 8.8PoC
2y ago

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

▾ Midnightnagios · nagios_xiEPSS 1.4%via NVD
CVE-2024-1442Medium· 6.0
2y ago

grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)

A flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9EPSS 0.80%via CSAF
CVE-2023-6507Medium· 6.1
2y ago

An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms

An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. When using the `extra_groups=` parameter with an empty list as a value (ie `ex…

▾ Sunlitpython · pythonEPSS 1.3%via NVD
CVE-2020-21046High· 7.8
4y ago

A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable

A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated non-administrative user to escalate thei…

▾ Twilightsoftonic · eaglegetEPSS 0.40%via NVD
CVE-2022-29333High· 7.8
4y ago

A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.

A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.

▾ Twilightcyberlink · powerdirectorEPSS 0.87%via NVD
CVE-2022-26251High· 7.2
4y ago

The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.

The HTTP interface of Synaman v5.1 and below was discovered to allow authenticated attackers to execute arbitrary code and escalate privileges.

▾ Twilightsynametrics · synamanEPSS 1.9%via NVD
CWE-269 vulnerabilities (CVEs) — page 15 · VulnSea