Search Results (3161 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-36954 1 Microsoft 10 Windows 10, Windows 10 1809, Windows 10 1909 and 7 more 2026-08-10 8.8 High
Windows Bind Filter Driver Elevation of Privilege Vulnerability
CVE-2021-36930 1 Microsoft 2 Edge, Edge Chromium 2026-08-10 5.3 Medium
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2021-36943 1 Microsoft 1 Azure Cyclecloud 2026-08-10 4 Medium
Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2021-36927 1 Microsoft 8 Windows 7, Windows 8.1, Windows Rt 8.1 and 5 more 2026-08-10 7.8 High
Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability
CVE-2021-34483 1 Microsoft 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more 2026-08-10 7.8 High
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-34471 1 Microsoft 1 Malware Protection Engine 2026-08-10 7.8 High
Microsoft Defender Elevation of Privilege Vulnerability
CVE-2021-36945 1 Microsoft 1 Windows 10 Update Assistant 2026-08-10 7.3 High
Windows 10 Update Assistant Elevation of Privilege Vulnerability
CVE-2021-34537 1 Microsoft 18 Windows 10, Windows 10 1507, Windows 10 1607 and 15 more 2026-08-10 7.8 High
Windows Bluetooth Driver Elevation of Privilege Vulnerability
CVE-2021-34487 1 Microsoft 10 Windows 10, Windows 10 1607, Windows 10 1809 and 7 more 2026-08-10 7 High
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2026-19360 1 Wongcyrus 1 Excellexbot 2026-08-10 4.7 Medium
A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2026-54415 1 Azuriom 1 Azuriom 2026-08-10 8.1 High
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}).
CVE-2026-40920 2026-08-10 N/A
Privilege Escalation via URL ParameterĀ is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVE-2026-15215 2 Wordpress, Wpswings 2 Wordpress, Subscriptions For Woocommerce 2026-08-08 8.8 High
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin before 2.0.1, resulting in remote code execution.
CVE-2024-8424 2 Watchgua, Watchguard 5 Panda Dome Firmware, Endpoint Security, Epdr Firmware and 2 more 2026-08-07 7.8 High
Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions.
CVE-2026-64637 1 Webpros 1 Plesk 2026-08-07 N/A
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
CVE-2026-19189 1 Poweriso 1 Poweriso 2026-08-07 7.8 High
A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper privilege management. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-48086 1 Open-reception 1 Appointment-booking-software 2026-08-07 9.9 Critical
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating their own tenant's staff. No policy check enforces that "only an existing GLOBAL_ADMIN may grant GLOBAL_ADMIN", so the schema validation IS the authorization decision. After re-login, the JWT contains the new role and the formerly-tenant-scoped admin reaches every other tenant on the platform. On the hosted OpenReception service this is a scope-changed escalation: a single customer-side tenant administrator gains full platform-wide administrative control over all other tenants' configuration, users, staff records, operational metadata, and tenant lifecycle. Plaintext appointment contents remain subject to the E2E model unless chained with the staff-crypto poisoning issue (V-4) or with staff-passkey hijacking (V-1). On a single-tenant self-hosted deployment it is still a privilege escalation because TENANT_ADMIN should not be able to create new tenants, modify global configuration, or manage other administrators. The same handler also accepts updates targeted at any colleague within the tenant. A tenant admin can promote a separate collaborator account instead of themselves, leaving their own audit trail clean while the platform-wide breach happens through a separate identity. Version 1.0.2 fixes the issue.
CVE-2026-16071 1 Redhat 8 Build Keycloak, Build Of Keycloak, Data Grid 8 and 5 more 2026-08-07 5.4 Medium
A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using a specific LDAP entry Distinguished Name (DN). Due to missing validation, the system allows lookups for users located outside the configured search boundary, leading to the disclosure of account information from unauthorized parts of the directory and unintended importing of those users into local storage.
CVE-2026-7327 1 Progress Software Corporation 1 Marklogic Server 2026-08-07 8.1 High
An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.
CVE-2026-7329 1 Progress Software Corporation 1 Marklogic Server 2026-08-07 9.9 Critical
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.