Skip to main content

CWE archive

CWE-269 CVEs

Programmatic archive

3,175 CVEs tagged with CWE-269404 Critical, 1,935 High, 751 Medium, 84 Low, 1 Unrated.

CVE-2026-45790

Published Aug 17, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.…

CVSS 8.0 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-75481

Published Aug 17, 2026

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, es…

CVSS 8.7 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-70495

Published Aug 17, 2026

A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluste…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-19996

Published Aug 17, 2026

A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-17533

Published Aug 16, 2026

The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators on multisite installations, all…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18432

Published Aug 16, 2026

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionU…

CVSS 9.8 · Critical
evidence mentions
12
Buzz score
32.1

CVE-2026-19928

Published Aug 16, 2026

A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the c…

CVSS 2.1 · Low
evidence mentions
10
Buzz score
32.0

CVE-2026-15142

Published Aug 15, 2026

The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-14279

Published Aug 15, 2026

The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request_send AJAX action. The ced_who…

CVSS 8.8 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-15312

Published Aug 15, 2026

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due to the `cre…

CVSS 8.8 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-15001

Published Aug 15, 2026

The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is due to the AJAX act…

CVSS 8.8 · High
evidence mentions
10
Buzz score
30.5

CVE-2026-63701

Published Aug 14, 2026

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access coul…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-63700

Published Aug 14, 2026

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-16772

Published Aug 14, 2026

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. Th…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-72833

Published Aug 14, 2026

The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted on a super-admin account bypass…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-72830

Published Aug 14, 2026

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers w…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-72829

Published Aug 14, 2026

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scop…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-72828

Published Aug 14, 2026

Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-groups decisions are gated on a ba…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-18039

Published Aug 14, 2026

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved account attributes, allowing unauthe…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-73842

Published Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/,…

CVSS 9.0 · Critical
evidence mentions
10
Buzz score
29.0

CVE-2026-73664

Published Aug 13, 2026

FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and app…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-73305

Published Aug 13, 2026

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-18249

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from Java-controlled addresses.

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18193

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18101

Published Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 3,175 CVEsPage 1 of 127