Skip to main content

CWE archive

CWE-250 CVEs

Programmatic archive

340 CVEs tagged with CWE-25056 Critical, 190 High, 88 Medium, 6 Low, 0 Unrated.

CVE-2026-14172

Published Jul 24, 2026

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-14985

Published Jul 22, 2026

The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8933

Published Jul 21, 2026

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environme…

CVSS 7.8 · High
evidence mentions
10
Buzz score
42.0

CVE-2026-15226

Published Jul 21, 2026

A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates gene…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13104

Published Jul 16, 2026

A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code wi…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-15584

Published Jul 13, 2026

A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged debug pods with host filesystem access in the shared default…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-42486

Published Jul 9, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-23562

Published Jul 9, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-23561

Published Jul 9, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-23560

Published Jul 9, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-23559

Published Jul 9, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with differen…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54319

Published Jun 23, 2026

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.186, a sandbox volume reference (volumeId, which may also be…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48584

Published Jun 19, 2026

Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12505

Published Jun 18, 2026

A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled envi…

CVSS 7.8 · High
evidence mentions
7
Buzz score
37.3

CVE-2026-47190

Published Jun 12, 2026

IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (crea…

CVSS 4.4 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-11626

Published Jun 10, 2026

CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege Escalation vulnerability, which is a type of issue whereby an attacker with limited pr…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50566

Published Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a tenant wit…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-50565

Published Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission buil…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-46618

Published Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, before the r…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-46617

Published Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, Fission runt…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-46748

Published Jun 9, 2026

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability.…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-11167

Published Jun 4, 2026

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perfor…

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-10843

Published Jun 4, 2026

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions ra…

CVSS 7.2 · High
evidence mentions
3
Buzz score
25.4

CVE-2025-12694

Published Jun 4, 2026

A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Cli…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 340 CVEsPage 1 of 14