VulnSea

CWE-269

CVEs classified under CWE-269, newest first.

470 CVEsRSS

CVE-2026-86893Low· 3.3
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to read device name.

▾ Sunlitapple · ipadosEPSS 0.14%via NVD
CVE-2026-46696Low· 3.3
1w ago

October System provides the system module for October Content Management System

October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. …

▾ Sunlitoctobercms · systemEPSS 0.27%via NVD
CVE-2026-90894High· 7.8
1w ago

Parallels Desktop runs prl_disp_service as root

Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, Pr…

▾ TwilightParallels · Parallels DesktopEPSS 0.17%via NVD
CVE-2026-12518High· 8.5
1w ago

A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.

A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.

▾ TwilightLogitech · Logi Options+EPSS 0.11%via NVD
CVE-2026-73470Critical· 9.8
1w ago

Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. …

Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. …

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.51%via NVD
CVE-2026-90787High· 7.3PoC
1w ago

A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e

A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow.…

▾ MidnightSoarkey · StudentManagementEPSS 0.54%via NVD
CVE-2026-90501Medium· 6.3PoC
2w ago

A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT

A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. …

▾ Twilightlenve · vhrEPSS 0.35%via NVD
CVE-2026-88764Medium· 5.4
2w ago

The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-price…

The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-price…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-86406High· 7.5
2w ago

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated …

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated …

▾ TwilightEPSS 0.32%via NVD
CVE-2026-80071High· 7.2
2w ago

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level acces…

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level acces…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-90523High· 7.3PoC
2w ago

A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09

A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java o…

▾ Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.50%via NVD
CVE-2026-87759High· 8.8
2w ago

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscri…

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscri…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-85681Critical· 9.8
2w ago

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allo…

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allo…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-15451High· 8.8
2w ago

The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39

The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the…

▾ TwilightMemberPress · MemberPress Corporate AccountsEPSS 0.24%via NVD
CVE-2026-77752High· 7.2
2w ago

The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a s…

The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a s…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-90487Medium· 4.3
2w ago

A vulnerability was found in Xuxueli xxl-job up to 3.4.2

A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation result…

▾ SunlitXuxueli · xxl-jobEPSS 0.35%via NVD
CVE-2026-85979High· 8.6
2w ago

Affected versions of Puppet Enterprise contain a command injection vulnerability

Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, …

▾ TwilightPerforce Software · Puppet EnterpriseEPSS 1.3%via NVD
CVE-2026-74925High· 7.2
2w ago

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-9327Medium· 6.3
2w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration

IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.

▾ Sunlitibm · websphere_application_serverEPSS 0.37%via NVD
CVE-2026-75777High· 8.8
2w ago

IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.

IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.

▾ TwilightIBM · Aspera Enterprise WebAppsEPSS 0.15%via NVD
CVE-2026-88891High· 8.3PoC
2w ago

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboard…

▾ MidnightOpenpanel-dev · openpanelEPSS 0.37%via NVD
CVE-2026-87958High· 8.1
2w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

▾ Twilightibm · db2EPSS 0.38%via NVD
CVE-2026-84042High· 7.8
2w ago

A flaw was found in crun

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The iss…

▾ TwilightRed Hat · crunEPSS 0.14%via NVD
CVE-2026-88863High· 8.1
2w ago

capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts

capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /priv…

▾ TwilightCap-go · capgo.appEPSS 0.39%via NVD
CVE-2026-81431High· 7.2
2w ago

The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-contro…

The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-contro…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-75927High· 7.2
2w ago

PublishPress Capabilities <= 2.50.0 - Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant

The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the `addPluginCa…

▾ Twilightpublishpress · User Role Editor – PublishPress Capabilities: Access Control and User RolesEPSS 0.64%via CVEORG
CVE-2026-86746Medium· 6.4PoC
2w ago

Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods

Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods. Attackers with a valid authenticated session can repl…

▾ Twilightsnipeitapp · snipe-itEPSS 0.29%via NVD
CVE-2026-87998High· 7.1
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge bas…

▾ Twilightopenwebui · open_webuiEPSS 0.49%via NVD
CVE-2026-73788Medium· 6.5
2w ago

A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment

A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root priv…

▾ SunlitHewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)EPSS 0.36%via NVD
CVE-2026-12858High· 8.5
2w ago

Improper Privilege Management vulnerability in ESET AV Remover (standalone) allows Privilege Escalation via especially crafted RPC.

Improper Privilege Management vulnerability in ESET AV Remover (standalone) allows Privilege Escalation via especially crafted RPC.

▾ TwilightESET spol. s.r.o. · ESET AV Remover (standalone)EPSS 0.10%via NVD
CWE-269 vulnerabilities (CVEs) — page 9 · VulnSea