Skip to main content

CWE archive

CWE-269 CVEs

Programmatic archive

2,989 CVEs tagged with CWE-269381 Critical, 1,798 High, 731 Medium, 78 Low, 1 Unrated.

CVE-2026-33552

Published May 27, 2026

Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.

CVSS 3.7 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-46424

Published May 27, 2026

Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/public/v1/roles/unassign) updates user documents in CouchDB but…

CVSS 4.2 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-45716

Published May 27, 2026

Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user wi…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-48926

Published May 27, 2026

Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate cre…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48923

Published May 27, 2026

Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connec…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8787

Published May 27, 2026

The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due to the `firebase_auth()`…

CVSS 8.8 · High
evidence mentions
6
Buzz score
34.5

CVE-2025-43306

Published May 26, 2026

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-9490

Published May 25, 2026

A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authen…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9489

Published May 25, 2026

NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal fun…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-6898

Published May 23, 2026

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' func…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-6897

Published May 23, 2026

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_s…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-6895

Published May 23, 2026

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and includin…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-6419

Published May 23, 2026

The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capabil…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-23663

Published May 22, 2026

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40172

Published May 22, 2026

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-9018

Published May 22, 2026

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel…

CVSS 8.8 · High
evidence mentions
5
Buzz score
27.9

CVE-2026-8327

Published May 21, 2026

Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw PO…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-5118

Published May 21, 2026

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'ro…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-45254

Published May 21, 2026

In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" instead of being rejected. In c…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7467

Published May 20, 2026

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' func…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-7284

Published May 20, 2026

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including,…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-31070

Published May 19, 2026

The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registra…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-8970

Published May 19, 2026

Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

CVSS 8.8 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-8957

Published May 19, 2026

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

CVSS 8.8 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort
Showing 276-300 of 2,989 CVEsPage 12 of 120