Export limit exceeded: 14873 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 10065 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10065 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-36927 | 1 Microsoft | 8 Windows 7, Windows 8.1, Windows Rt 8.1 and 5 more | 2026-08-10 | 7.8 High |
| Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability | ||||
| CVE-2021-34483 | 1 Microsoft | 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more | 2026-08-10 | 7.8 High |
| Windows Print Spooler Elevation of Privilege Vulnerability | ||||
| CVE-2021-34471 | 1 Microsoft | 1 Malware Protection Engine | 2026-08-10 | 7.8 High |
| Microsoft Defender Elevation of Privilege Vulnerability | ||||
| CVE-2021-36945 | 1 Microsoft | 1 Windows 10 Update Assistant | 2026-08-10 | 7.3 High |
| Windows 10 Update Assistant Elevation of Privilege Vulnerability | ||||
| CVE-2021-34537 | 1 Microsoft | 18 Windows 10, Windows 10 1507, Windows 10 1607 and 15 more | 2026-08-10 | 7.8 High |
| Windows Bluetooth Driver Elevation of Privilege Vulnerability | ||||
| CVE-2021-34487 | 1 Microsoft | 10 Windows 10, Windows 10 1607, Windows 10 1809 and 7 more | 2026-08-10 | 7 High |
| Windows Event Tracing Elevation of Privilege Vulnerability | ||||
| CVE-2026-19360 | 1 Wongcyrus | 1 Excellexbot | 2026-08-10 | 4.7 Medium |
| A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer. | ||||
| CVE-2026-54415 | 1 Azuriom | 1 Azuriom | 2026-08-10 | 8.1 High |
| Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}). | ||||
| CVE-2026-66662 | 2 Shabti, Wordpress | 2 Frontend Admin By Dynamapps, Wordpress | 2026-08-08 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||
| CVE-2026-15215 | 2 Wordpress, Wpswings | 2 Wordpress, Subscriptions For Woocommerce | 2026-08-08 | 8.8 High |
| The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution. | ||||
| CVE-2026-19152 | 1 Google | 1 Chrome | 2026-08-08 | 8.3 High |
| Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-19192 | 1 Deepcool | 1 Displayservice | 2026-08-08 | 7.8 High |
| A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit is now public and may be used. | ||||
| CVE-2024-8424 | 2 Watchgua, Watchguard | 5 Panda Dome Firmware, Endpoint Security, Epdr Firmware and 2 more | 2026-08-07 | N/A |
| Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions. | ||||
| CVE-2026-19244 | 1 Nanobot | 1 Nanobot | 2026-08-07 | 4.7 Medium |
| A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP enabledTools Scope Handler. Performing a manipulation results in improper access controls. The attack is possible to be carried out remotely. The exploit is now public and may be used. Upgrading to version 0.3.0 is sufficient to fix this issue. The patch is named 4436. You should upgrade the affected component. Multiple issues were reported to the project. They reacted with a high level of professionalism and kindness: "Both reports describe the same root cause: MCP resource and prompt wrappers could be registered outside the intended enabledTools scope. The registration boundary was corrected". | ||||
| CVE-2026-64637 | 1 Webpros | 1 Plesk | 2026-08-07 | N/A |
| Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account. | ||||
| CVE-2026-19190 | 1 Stablebit | 1 Scanner | 2026-08-07 | 7.8 High |
| A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission issues. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. | ||||
| CVE-2026-19191 | 1 Stablebit | 1 Drivepool | 2026-08-07 | 7.8 High |
| A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2026-19189 | 1 Poweriso | 1 Poweriso | 2026-08-07 | 7.8 High |
| A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper privilege management. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2026-48086 | 1 Open-reception | 1 Appointment-booking-software | 2026-08-07 | 9.9 Critical |
| OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating their own tenant's staff. No policy check enforces that "only an existing GLOBAL_ADMIN may grant GLOBAL_ADMIN", so the schema validation IS the authorization decision. After re-login, the JWT contains the new role and the formerly-tenant-scoped admin reaches every other tenant on the platform. On the hosted OpenReception service this is a scope-changed escalation: a single customer-side tenant administrator gains full platform-wide administrative control over all other tenants' configuration, users, staff records, operational metadata, and tenant lifecycle. Plaintext appointment contents remain subject to the E2E model unless chained with the staff-crypto poisoning issue (V-4) or with staff-passkey hijacking (V-1). On a single-tenant self-hosted deployment it is still a privilege escalation because TENANT_ADMIN should not be able to create new tenants, modify global configuration, or manage other administrators. The same handler also accepts updates targeted at any colleague within the tenant. A tenant admin can promote a separate collaborator account instead of themselves, leaving their own audit trail clean while the platform-wide breach happens through a separate identity. Version 1.0.2 fixes the issue. | ||||
| CVE-2025-4374 | 1 Redhat | 1 Quay | 2026-08-07 | 6.5 Medium |
| A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository. | ||||