Skip to main content

CWE archive

CWE-269 CVEs

Programmatic archive

2,948 CVEs tagged with CWE-269374 Critical, 1,769 High, 727 Medium, 77 Low, 1 Unrated.

CVE-2026-53645

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged staff account to grant arbitrary module permissions to itse…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-14719

Published Jul 5, 2026

A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file register.php of the component R…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-46680

Published Jul 1, 2026

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 3…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-13228

Published Jul 1, 2026

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5…

CVSS 8.8 · High
evidence mentions
8
Buzz score
37.0

CVE-2026-12224

Published Jul 1, 2026

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, 5.0.4. This is due to the `up…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-57995

Published Jun 30, 2026

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary rights to groups…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-14124

Published Jun 30, 2026

Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malic…

CVSS 7.8 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-14101

Published Jun 30, 2026

Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform…

CVSS 9.6 · Critical
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2025-7406

Published Jun 30, 2026

Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root pr…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-58054

Published Jun 28, 2026

MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers the Administrators group (gid 4)…

CVSS 8.6 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-58053

Published Jun 28, 2026

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with priv…

CVSS 9.4 · Critical
evidence mentions
4
Buzz score
29.1

CVE-2026-12415

Published Jun 27, 2026

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
32.9

CVE-2026-45256

Published Jun 26, 2026

When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation was permitted but did not check the result before deliveri…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-52808

Published Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/repos/:owner/:repo/wiki, and P…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-56245

Published Jun 24, 2026

Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time RPC function that allows unauthenticated attackers to inser…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-54319

Published Jun 23, 2026

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.186, a sandbox volume reference (volumeId, which may also be…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-56225

Published Jun 23, 2026

Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers (get/put/delete/post). API keys created with mode=all but restricted…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-8157

Published Jun 22, 2026

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authentica…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-56239

Published Jun 21, 2026

Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY DEFINER function, which performs sensitive billing operati…

CVSS 7.2 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-56216

Published Jun 20, 2026

Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API keys to mint unrestricted keys by setting emp…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-56212

Published Jun 20, 2026

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authentication…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-50201

Published Jun 17, 2026

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-20246

Published Jun 17, 2026

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerabil…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-54415

Published Jun 17, 2026

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.acce…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9
Showing 101-125 of 2,948 CVEsPage 5 of 118