Skip to main content

CWE archive

CWE-269 CVEs

Programmatic archive

3,070 CVEs tagged with CWE-269383 Critical, 1,868 High, 739 Medium, 79 Low, 1 Unrated.

CVE-2026-14328

Published Jul 28, 2026

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1.…

CVSS 8.8 · High
evidence mentions
7
Buzz score
27.3

CVE-2026-14545

Published Jul 28, 2026

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthen…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-66015

Published Jul 27, 2026

An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary plat…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-66399

Published Jul 27, 2026

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join p…

CVSS 8.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-13152

Published Jul 27, 2026

The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key o…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12394

Published Jul 27, 2026

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitr…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-12502

Published Jul 24, 2026

Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `supera…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16743

Published Jul 24, 2026

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed by the…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-10610

Published Jul 24, 2026

Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-7483

Published Jul 24, 2026

Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12981

Published Jul 24, 2026

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the passw…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12497

Published Jul 24, 2026

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12736

Published Jul 24, 2026

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /…

CVSS 8.0 · High
evidence mentions
8
Buzz score
28.5

CVE-2026-16764

Published Jul 23, 2026

A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such man…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-38764

Published Jul 23, 2026

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

CVSS 7.8 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-34496

Published Jul 23, 2026

Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-15630

Published Jul 23, 2026

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorizatio…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-65897

Published Jul 23, 2026

Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accou…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-15017

Published Jul 23, 2026

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and no…

CVSS 8.8 · High
evidence mentions
6
Buzz score
26.0

CVE-2026-61246

Published Jul 22, 2026

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60455

Published Jul 22, 2026

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60439

Published Jul 22, 2026

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60373

Published Jul 22, 2026

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60371

Published Jul 22, 2026

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 3,070 CVEsPage 1 of 123