VulnSea

CWE-269

CVEs classified under CWE-269, newest first.

470 CVEsRSS

CVE-2026-76670Critical· 9.9
1w ago

Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator

Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administr…

▾ Midnightarubanetworks · edgeconnect_sd-wan_orchestratorEPSS 0.50%via NVD
CVE-2026-76677High· 8.8
1w ago

A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways

A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface lea…

▾ TwilightHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.54%via NVD
CVE-2026-76678High· 8.8
1w ago

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to …

▾ TwilightHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.63%via NVD
CVE-2026-76687High· 7.5
1w ago

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow a low-privilege authenticated remote attacker to escalate privileges

A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow a low-privilege authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker…

▾ Twilightarubanetworks · edgeconnect_sd-wan_orchestratorEPSS 0.47%via NVD
CVE-2026-76694Medium· 6.6
1w ago

A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways

A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges bey…

▾ SunlitHewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN GatewaysEPSS 0.54%via NVD
CVE-2026-76669Critical· 9.9
1w ago

Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator

Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administr…

▾ Midnightarubanetworks · edgeconnect_sd-wan_orchestratorEPSS 0.50%via NVD
CVE-2026-79411High· 8.8PoC
1w ago

Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator

Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoin…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-0179Medium· 6.7
1w ago

In Bootloader, there is a possible permission bypass due to a missing permission check

In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-65831High· 7.7
1w ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions …

▾ TwilightArcadeData · arcadedbEPSS 0.60%via NVD
CVE-2026-14805High· 8.8
1w ago

The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16

The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint in admin/admin-n…

▾ TwilightStylemixThemes · Consulting - Business, Finance WordPress ThemeEPSS 0.31%via NVD
CVE-2026-92015High· 8.8
1w ago

Privilege escalation in the WebExtensions component

Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.28%via NVD
CVE-2026-92017High· 8.8
1w ago

Privilege escalation in the DOM: Service Workers component

Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.26%via NVD
CVE-2026-92033High· 8.8
1w ago

Privilege escalation in Firefox for Android

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.

▾ TwilightMozilla · FirefoxEPSS 0.37%via NVD
CVE-2026-92047High· 8.8⚖ disputed
1w ago

Privilege escalation in the Crash Reporting component

Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.44%via NVD
CVE-2026-92055High· 8.8⚖ disputed
1w ago

Privilege escalation in the DevTools component

Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.44%via NVD
CVE-2026-92053High· 8.8⚖ disputed
1w ago

Privilege escalation in the Graphics: CanvasWebGL component

Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.48%via NVD
CVE-2026-92062High· 8.8⚖ disputed
1w ago

Privilege escalation in the Session Restore component

Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.44%via NVD
CVE-2026-92073High· 8.8⚖ disputed
1w ago

Privilege escalation in the Enterprise Policies component

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.44%via NVD
CVE-2026-75983High· 7.5
1w ago

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions…

▾ Twilightarraytics · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceEPSS 0.70%via NVD
CVE-2026-90856High· 7.3PoC
1w ago

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role …

▾ MidnightSourceCodester · College Notes Gallery Management SystemEPSS 0.50%via NVD
CVE-2026-54168Medium· 6.5
1w ago

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the …

▾ Sunlittektoncd · pipelines-as-codeEPSS 0.59%via NVD
CVE-2026-61549Critical· 9.0
1w ago

Woodpecker is a CI/CD engine

Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pip…

▾ Midnightwoodpecker-ci · woodpeckerEPSS 0.28%via NVD
CVE-2026-55225High· 8.0
1w ago

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator wat…

▾ Twilightstrimzi · strimzi-kafka-operatorEPSS 0.29%via NVD
CVE-2026-55226Medium· 5.4
1w ago

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom res…

▾ Sunlitstrimzi · strimzi-kafka-operatorEPSS 0.25%via NVD
CVE-2026-64753Medium· 6.5
1w ago

A permissions issue was addressed by removing the vulnerable code

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose se…

▾ Sunlitapple · safariEPSS 0.30%via NVD
CVE-2026-84603Medium· 5.5
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2026-65354High· 8.2
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. A malicious app may be able to break out of its sandbox.

▾ Twilightapple · ipadosEPSS 0.14%via NVD
CVE-2026-86884Medium· 5.5
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An app may be able to access sensitive user data.

▾ Sunlitapple · ipadosEPSS 0.14%via NVD
CVE-2026-84587Medium· 5.5
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.

▾ Sunlitapple · macosEPSS 0.15%via NVD
CVE-2026-86888Low· 3.3
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A local app may be able to read a persistent account i…

▾ Sunlitapple · ipadosEPSS 0.14%via NVD
CWE-269 vulnerabilities (CVEs) — page 8 · VulnSea