By weakness (CWE)

CWE-269: related vulnerabilities

CVEs classified under CWE-269. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

92 published vulnerabilities

  • CVE-2026-11108HIGH 8.8

    A flaw in how Google Chrome handles NFC (Near Field Communication) on Android devices allows an attacker to trick a user into visiting a malicious website, which can then escape the browser sandbox and gain elevated privileges on the device. The vulnerability requires user interaction—specifically clicking a link or visiting a page—but does not require the attacker to be network-adjacent or have special system access. Once exploited, an attacker gains the same privileges as the Chrome browser process, potentially enabling access to sensitive data or further system compromise.

  • CVE-2026-11295HIGH 8.8

    A vulnerability in Google Chrome's WebView on Android allows attackers to escalate their privileges by tricking users into visiting a specially crafted webpage. WebView is the component that renders web content within Android apps, so this affects not just Chrome but any app built on this framework. An attacker needs user interaction (clicking or viewing the malicious page), but once triggered, the vulnerability grants them elevated system permissions—a significant breach of the Android security model.

  • CVE-2026-11616HIGH 8.8

    The Events Calendar for GeoDirectory WordPress plugin contains a privilege escalation flaw that allows authenticated users with Subscriber-level permissions to become Administrator. An attacker can manipulate input fields in a specific AJAX handler to inject WordPress capability data directly into their user profile, granting them full admin rights. This affects versions up to 2.3.28 and requires only valid WordPress account credentials to exploit.

  • CVE-2026-12018HIGH 8.8

    A flaw in Chrome's Mojo implementation on Windows allows a local attacker to gain system-level control by tricking a user into opening a malicious file. The vulnerability affects Chrome versions before 149.0.7827.115 and has been rated High severity by Google's security team.

  • CVE-2026-12165HIGH 8.8

    The Contest Gallery WordPress plugin contains a privilege escalation flaw affecting versions up to 30.0.2. A contributor-level user can manipulate a plugin setting to trick the system into promoting their Google sign-in account to administrator. The vulnerability exists because the plugin grants access to its admin pages at a low capability level (allowing contributors through) but fails to validate that a critical user role setting stays within safe bounds. Once changed, any new Google account signing in via that setting gets those elevated permissions.

  • CVE-2026-12289HIGH 8.8

    A privilege escalation vulnerability exists in Firefox and Thunderbird's WebRender graphics component. An attacker can exploit this through a malicious webpage to gain elevated privileges on a user's system. The vulnerability requires user interaction (visiting a crafted site) but needs no authentication and can be triggered remotely over the network. The impact is severe—an attacker could read sensitive files, modify system data, or execute arbitrary code with higher-level access.

  • CVE-2026-12448HIGH 8.8

    A weakness in Google Chrome's WebView component on Android devices allows attackers to trick users into visiting a specially crafted webpage that can escape the security boundaries of the browser and gain elevated privileges on the device. This is a remote attack that requires user interaction—the victim must click a link or visit a malicious site—but once triggered, it bypasses normal Android permission models. The vulnerability affects Chrome versions prior to 149.0.7827.155.

  • CVE-2026-46827HIGH 8.8

    CVE-2026-46827 is a high-severity vulnerability in Oracle E-Business Suite's Payroll module that allows a low-privileged network attacker to gain full control over the payroll system. An authenticated user with minimal permissions can exploit this flaw remotely via HTTP to read sensitive data, modify payroll records, or disrupt service availability. This represents a complete compromise of the affected payroll component.

  • CVE-2026-46837HIGH 8.8

    A vulnerability exists in Oracle Flow Manufacturing (part of Oracle E-Business Suite) that allows a low-privileged user with network access to gain complete control over the affected system. An attacker who already has valid credentials can exploit a flaw in the security component via SQL to read, modify, or delete data—or disrupt system operations entirely. The vulnerability affects Oracle E-Business Suite versions 12.2.9 through 12.2.15.

  • CVE-2026-46885HIGH 8.8

    A vulnerability exists in Oracle Siebel CRM's integration component (EAI) that allows a low-privilege user with network access to take complete control of the affected system. The flaw is straightforward to exploit and requires only standard HTTP access—no complex attack setup needed. An attacker who already has basic user credentials can escalate to full compromise, affecting data confidentiality, system integrity, and availability. Versions 17.0 through 26.5 are vulnerable.

  • CVE-2026-46903HIGH 8.8

    A vulnerability in Oracle JD Edwards EnterpriseOne Tools allows a user with basic network access and low-level system privileges to gain complete control over the application. The flaw resides in the business logic security layer and can be exploited without user interaction or complex attack setup. An attacker leveraging this vulnerability could read sensitive financial data, modify business records, or disrupt operations.

  • CVE-2026-46916HIGH 8.8

    A high-severity flaw in Oracle's Process Manufacturing Product Development component (part of E-Business Suite) allows authenticated users with low-level network access to gain full control over the affected system. An attacker who has obtained basic credentials can exploit this over the network to read sensitive data, modify critical information, and disrupt operations without requiring user interaction. Versions 12.2.3 through 12.2.15 are vulnerable.

  • CVE-2026-46921HIGH 8.8

    A high-severity vulnerability exists in Oracle Siebel CRM Cloud Manager that allows a low-privileged attacker with network access to take over the entire application. The flaw affects Siebel CRM versions 17.0 through 26.5 and requires only standard HTTP access—no user interaction or elevated privileges needed beyond basic network authentication. Attackers exploiting this could gain full control over confidentiality, integrity, and availability of the system.

  • CVE-2026-46928HIGH 8.8

    A vulnerability in Oracle Spares Management, part of Oracle E-Business Suite, allows users with standard network access and basic system credentials to gain complete control over the application. An attacker with low-level privileges can exploit this flaw remotely via HTTPS to read sensitive data, modify records, and disrupt operations. The vulnerability affects versions 12.2.3 through 12.2.15.

  • CVE-2026-46929HIGH 8.8

    CVE-2026-46929 is a high-severity vulnerability in Oracle's Cost Management component within Oracle E-Business Suite (versions 12.2.3 through 12.2.15). An attacker with a low-level user account and network access can exploit this flaw via HTTP to gain complete control over the Cost Management system. The vulnerability requires no user interaction, making it straightforward to exploit. Successful exploitation allows attackers to read sensitive data, modify cost planning information, and disrupt system availability.

  • CVE-2026-46937HIGH 8.8

    A vulnerability in Oracle iSetup (a configuration and setup component of Oracle E-Business Suite) allows an authenticated user with basic network access to take control of the iSetup application. The flaw affects versions 12.2.3 through 12.2.15. Because the vulnerability requires low-level credentials but no user interaction, it presents significant risk in environments where contractor, vendor, or junior staff accounts exist—anyone with a valid login can trigger the compromise without special tools or social engineering.

  • CVE-2026-46940HIGH 8.8

    CVE-2026-46940 is a critical vulnerability in Oracle Cost Management, a component of Oracle E-Business Suite. An attacker with a low-level user account and network access can exploit this flaw to take over the entire Cost Management system. The vulnerability is network-accessible, does not require user interaction, and can compromise confidentiality, integrity, and availability of the affected system. Organizations running Oracle E-Business Suite versions 12.2.3 through 12.2.15 should treat this as an urgent security matter.

  • CVE-2026-46942HIGH 8.8

    A vulnerability in Oracle's Process Manufacturing Process Planning component allows attackers with low-level network access to take over the system. The flaw affects versions 12.2.3 through 12.2.15 of the Oracle E-Business Suite module and requires an attacker to have valid user credentials, but no special privileges or user interaction. Once exploited, an attacker gains complete control over the affected application, compromising all data confidentiality, system integrity, and availability.

  • CVE-2026-46951HIGH 8.8

    A vulnerability in Oracle Quality, part of Oracle E-Business Suite, allows an authenticated attacker to gain complete control over the Oracle Quality system. The attacker only needs basic user-level network access via HTTP to trigger the flaw. Once exploited, an attacker can read, modify, or delete sensitive data and disrupt quality operations. The vulnerability affects Oracle Quality versions 12.2.3 through 12.2.15.

  • CVE-2026-46952HIGH 8.8

    A vulnerability in Oracle Quality, part of Oracle E-Business Suite, allows users with basic system access to take complete control of the application via network requests. The flaw affects Oracle Quality versions 12.2.3 through 12.2.15 and requires only low-level credentials to exploit—no special tricks or user interaction needed. Successful exploitation grants an attacker the ability to read, modify, and delete data, or disable the system entirely.

  • CVE-2026-46961HIGH 8.8

    A critical vulnerability in Oracle Project Portfolio Analysis allows authenticated users with basic network access to gain full control over the application. An attacker with a low-privilege account can exploit this flaw to read, modify, or delete sensitive project data and disrupt service availability. The vulnerability affects multiple versions of the product (12.2.3 through 12.2.15) and requires only HTTP connectivity—no special conditions or user interaction needed once the attacker gains initial access credentials.

  • CVE-2026-46962HIGH 8.8

    A vulnerability in Oracle Project Portfolio Analysis (part of Oracle E-Business Suite) allows someone with basic network access and low-level user credentials to take complete control of the system. The flaw affects versions 12.2.3 through 12.2.15 and requires only a standard user account and HTTP access—no special techniques needed. Once exploited, an attacker gains the ability to read sensitive data, modify information, and disrupt operations.

  • CVE-2026-46972HIGH 8.8

    A flaw in Oracle's Outsourced Manufacturing for Discrete Industries module (versions 12.2.3 through 12.2.15) allows attackers who have basic user-level network access to fully compromise the system. An attacker with low-privilege credentials can exploit this vulnerability over HTTP to gain complete control over the application, potentially reading, modifying, or destroying sensitive manufacturing data. The vulnerability requires only standard network connectivity and user credentials to trigger—no social engineering or complex exploitation steps are needed.

  • CVE-2026-46973HIGH 8.8

    A vulnerability in Oracle's Outsourced Manufacturing for Discrete Industries (part of E-Business Suite) allows attackers with basic user credentials to gain complete control over the system via the network. The flaw affects all versions from 12.2.3 through 12.2.15 and poses a severe risk because an attacker with low-level access can bypass controls to read, modify, or delete critical manufacturing data.

  • CVE-2026-54099HIGH 8.8

    A vulnerability in Red Hat's Windows Machine Config Operator for OpenShift allows a compromised Windows worker node to escalate privileges to cluster administrator. The flaw exists in how the system validates certificate requests—it checks that requests contain a specific organization field (system:wicd-nodes) but fails to reject requests that also include additional organization values like system:masters. An attacker with access to WICD credentials on a Windows node can exploit this gap to obtain a certificate granting full cluster control.

  • CVE-2026-56216HIGH 8.8

    Capgo versions before 12.128.2 contain a privilege escalation flaw that allows attackers who compromise an app-limited API key to escalate it into a fully unrestricted key with organization-wide access. The vulnerability exists in the API key minting endpoint and can be exploited by setting empty permission limits during key creation. This means an attacker with a limited-scope key could gain access to sensitive resources across the entire organization, including app listings and other protected endpoints.

  • CVE-2026-6226HIGH 8.8

    The Frontend Admin plugin for WordPress, maintained by DynamiApps, contains a critical flaw that allows attackers to create administrator accounts without authentication. The vulnerability exists because the plugin accepts form definitions directly from user input rather than retrieving them securely from the database. By crafting a malicious form submission, an attacker can bypass role validation and create a new administrator account, gaining complete control of the WordPress site.

  • CVE-2026-7465HIGH 8.8

    Spectra Gutenberg Blocks, a WordPress plugin used for building websites with the block editor, contains a critical flaw that allows authenticated contributors and above to execute arbitrary code on the web server. The attack exploits the plugin's block rendering system: an attacker creates a custom block type with a malicious callback function, then triggers it through a second block in the same post, causing the server to run the attacker's code. This affects all versions up to 2.19.25.

  • CVE-2026-8157HIGH 8.8

    The Vitepos WordPress plugin before version 3.4.2 contains a privilege escalation flaw in its REST API. Authenticated users with limited roles can exploit a role-assignment weakness to elevate themselves to administrator status, granting full control of the WordPress site. This requires an attacker to already have valid WordPress credentials, but does not require administrator access initially.

  • CVE-2026-9999HIGH 8.8

    A flaw in ANGLE, the graphics rendering component within Google Chrome on macOS, allows attackers to break out of the sandbox and run arbitrary code on an affected system. An attacker only needs to trick a user into visiting a malicious webpage—no special permissions or complex attack chains required. The vulnerability has a High severity rating and affects Chrome versions prior to 148.0.7778.216 on Mac systems.

  • CVE-2026-44543HIGH 8.7

    A flaw in Rancher's Local Path Provisioner allows users with permission to modify a specific Kubernetes configuration file to inject malicious settings into helper pods. These pods run with elevated privileges and can access sensitive host files, other applications' data, and credentials stored on the node. The vulnerability requires the attacker to have legitimate access to edit the configuration—they cannot exploit it remotely or without credentials. The issue is resolved in version 0.0.36.

  • CVE-2026-46804HIGH 8.7

    Oracle WebCenter Content version 14.1.2.0.0 contains a privilege escalation vulnerability affecting the Content Server component. A low-privileged attacker with network access can exploit this flaw to read sensitive data or modify critical business information. The attack requires the attacker to trick a legitimate user into performing an action—such as clicking a link or opening a document—but the impact extends beyond WebCenter itself, potentially affecting connected systems and downstream applications that depend on WebCenter data.

  • CVE-2026-50570HIGH 8.5

    Fission, a Kubernetes-native serverless framework, has a flaw in how it validates which Linux capabilities tenants are allowed to add to containers. The framework maintains a denylist of dangerous capabilities to prevent privilege escalation, but the list was incomplete—it missed CAP_SYS_TIME and others. This means a tenant could create a Function or Environment and request CAP_SYS_TIME, which would pass validation and allow their code to run with the ability to modify system time. This is a privilege escalation vulnerability that affects multi-tenant Fission clusters where untrusted users can define workloads.

  • CVE-2026-35272HIGH 8.4

    Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 contain a local privilege escalation vulnerability in the Deployment Package component. An attacker with legitimate access to the infrastructure hosting PeopleSoft can exploit this flaw without authentication to gain complete control over the PeopleSoft system, compromising confidentiality, integrity, and availability. The vulnerability carries a CVSS score of 8.4 (HIGH severity).

  • CVE-2026-39118HIGH 8.4

    Kandji Agent versions before 4.7.5(5374) contain a privilege escalation vulnerability that allows an attacker with local access to bypass client-side validation checks and invoke functionality that should be restricted. An unauthenticated local user can exploit this weakness to gain higher privileges on the affected system without user interaction.

  • CVE-2025-5088HIGH 8.3

    CVE-2025-5088 is a privilege escalation vulnerability in CVX clusters that allows an authenticated attacker with Redis access to gain root-level control across all servers in the cluster. The exploit requires two prerequisites: network connectivity to the Redis service and possession of the Redis password. Currently, Redis communication—including password authentication—occurs in plaintext, making credentials vulnerable to interception on the network. This is a significant insider threat and network-access risk for organizations running CVX infrastructure.

  • CVE-2026-56225HIGH 8.3

    Capgo versions before 12.128.2 contain a flaw in how they validate API key permissions. When an API key is created with restricted scope (limited to a specific application), the system fails to properly enforce that restriction. Instead of checking whether the key is authorized to access a particular app, the system only checks organizational scope, allowing a scoped API key to view, modify, or delete other API keys at the account level—even those outside its intended app boundaries. This breaks a fundamental security assumption: that app-scoped credentials should only touch resources within that app.

  • CVE-2026-9892HIGH 8.3

    A vulnerability in Google Chrome's Skia graphics library on Android could allow an attacker who has already gained control of Chrome's renderer process to break out of the browser sandbox and execute arbitrary code with elevated privileges. An attacker would need to trick a user into visiting a specially crafted website while the renderer has been compromised—a two-step attack requiring both initial compromise and user interaction.

  • CVE-2026-35288HIGH 8.2

    Oracle PeopleSoft Enterprise PT PeopleTools contains a privilege escalation vulnerability in its Deployment Package component that allows a high-privileged local attacker to take complete control of the system. The flaw affects versions 8.61 and 8.62, and because PeopleTools is a critical deployment and configuration tool used across PeopleSoft environments, a successful compromise can cascade to impact other connected systems and data. The vulnerability requires the attacker to already have high-level access to the infrastructure where PeopleTools runs, which narrows the immediate threat surface but represents significant risk in environments where privileged access is less tightly controlled.

  • CVE-2026-56245HIGH 8.2

    Supabase Capgo versions before 12.128.2 contain a flaw that lets anyone call a specific API function without proving who they are. An attacker can use this to create fake billing records for any organization, which could lead to inflated costs, resource quotas being consumed, or one tenant's usage being charged to another. The vulnerability requires no special privileges or user interaction—just a network connection and knowledge of the function name.

  • CVE-2026-54415HIGH 8.1

    Azuriom CMS versions before 1.2.11 contain a missing authorization flaw in server management routes that allows authenticated administrators with the admin.access permission to escalate privileges and take over regular user accounts. An attacker with admin credentials can create AzLink server tokens and use API endpoints to forcibly change user passwords and email addresses, effectively locking legitimate users out of their accounts and taking complete control of them.

  • CVE-2025-31272HIGH 7.8

    A vulnerability in macOS allows locally authenticated applications to circumvent built-in launch constraint protections—security mechanisms designed to prevent unauthorized code execution. An attacker with local access could potentially run malicious code with elevated system privileges by exploiting a weakness in how these protections are enforced. Apple has patched this issue in macOS Sequoia 15.4 with stricter validation checks.

  • CVE-2026-0009HIGH 7.8

    A logic error in Android allows a local attacker to hijack touch input through tapjacking attacks, potentially gaining elevated privileges on the device. No special permissions or user interaction are required for exploitation, making this a direct path to privilege escalation for any app already running on the compromised system.

  • CVE-2026-0019HIGH 7.8

    CVE-2026-0019 is a privilege escalation vulnerability in Android's SettingsLib component that allows a local attacker with basic user-level access to disable critical system components and escalate their privileges to a higher level of control. The vulnerability stems from a logic error in the code and requires no user interaction to exploit, making it a straightforward attack vector for any app or process running on an affected device.

  • CVE-2026-0063HIGH 7.8

    A logic error in Android's phone service management allows a local attacker with basic user privileges to bypass carrier restrictions on a device. The vulnerability exists in code that controls which carriers are allowed to operate on the phone, and exploiting it requires only local access—no special permissions, user interaction, or additional steps. An attacker who gains a foothold on the device can remove or alter these carrier controls, potentially hijacking the device's cellular identity or enabling unauthorized network operations.

  • CVE-2026-0089HIGH 7.8

    CVE-2026-0089 is a vulnerability in Android's PackageInstallerService that allows a local attacker with basic user-level permissions to bypass security checks and install applications without proper verification. Because the vulnerability exists in multiple functions that lack proper permission validation, an attacker can escalate their privileges by sidestepping the normal app installation safeguards. No user interaction or special device access is required to exploit this flaw once an attacker has obtained standard user privileges on the device.

  • CVE-2026-0091HIGH 7.8

    A privilege escalation vulnerability exists in Android where an over-privileged shell user can execute arbitrary code within the launcher process. An attacker with local access can exploit this weakness to gain elevated privileges without needing special execution rights or user interaction. This is a local-only threat that targets the core launcher functionality central to Android's user interface and app management.

  • CVE-2026-11103HIGH 7.8

    A flaw in Google Chrome's installer on Windows allows a local attacker to gain administrative privileges on a computer by tricking a user into opening a malicious file. The vulnerability exists in how the installer validates and processes files during installation or updates. While Chrome itself is a web browser, this weakness targets the installation mechanism—the software that sets up Chrome on your system—making it a local privilege escalation risk rather than a remote internet-based attack.

  • CVE-2026-12217HIGH 7.8

    DVDFab Virtual Drive version 2.0.0.5 contains a privilege escalation vulnerability in its signed kernel driver component (dvdfabio.sys). A local user with standard privileges can exploit this flaw to gain elevated system access, potentially allowing them to modify system files, install malware, or disable security controls. The vulnerability requires local access and user interaction is not needed once code execution begins. Public exploit code is available, increasing the urgency for affected organizations.

  • CVE-2026-36213HIGH 7.8

    Microvirt MEmu Android Emulator version 9.2.7.0 contains a local privilege escalation vulnerability in its MemuService.exe component. An attacker with standard user-level access on a system running this emulator version can exploit an improper permission or privilege assignment flaw to gain elevated (administrator-level) privileges. This vulnerability requires local access and cannot be exploited remotely.

  • CVE-2026-45176HIGH 7.8

    Idira Endpoint Privilege Manager Agent contains a flaw in how it controls access to high-privileged components. An attacker with a regular user account on the same system can manipulate how the agent communicates internally or intercept file operations to trick it into performing actions it shouldn't allow. This could let them gain elevated privileges and take unauthorized actions on the machine. The vulnerability affects versions before 26.5.

  • CVE-2026-49189HIGH 7.8

    CVE-2026-49189 is a privilege escalation vulnerability in Acer Connect M6E 5G devices where a core system component (Broadcast Receiver) fails to enforce access controls. Any application installed on the device—even one with minimal permissions—can trigger administrative operations that should be restricted. This bridges the gap between a low-privilege app and high-impact actions, allowing local attackers to escalate their capabilities without user interaction.

  • CVE-2026-56239HIGH 7.6

    Capgo versions before 12.128.2 contain a billing privilege escalation flaw in a Supabase database function that handles usage overage charges. The function runs with elevated database owner privileges but fails to verify that the user initiating the request actually has authorization to modify billing for the target organization. An authenticated user could exploit this via remote API calls to tamper with billing records, deduct credits from other organizations' accounts, or inject fraudulent overage charges without proper authorization checks.

  • CVE-2026-11296HIGH 7.5

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the ImageCapture feature handles certain operations, allowing an attacker who has already compromised the browser's rendering engine to gain elevated privileges on the system. The attacker would need to trick the user into visiting a malicious webpage while the renderer process is already under their control. This is a privilege escalation vulnerability rather than a remote code execution vulnerability, meaning the initial compromise must have already occurred.

  • CVE-2026-46873HIGH 7.5

    Oracle VM VirtualBox 7.2.8 contains a vulnerability in its VMSVGA device emulation that could allow an attacker with high privileges and local access to compromise the hypervisor and potentially affect systems beyond VirtualBox itself. The flaw is difficult to exploit in practice but could lead to complete control of the virtualization environment if successfully weaponized.

  • CVE-2026-46934HIGH 7.5

    A vulnerability in Oracle's Complex Maintenance, Repair and Overhaul component of E-Business Suite allows attackers with low-level network access to gain complete control over the application. The flaw requires an attacker to already be authenticated with basic user credentials and involves HTTP-based exploitation, but once leveraged successfully, gives an adversary full read, write, and availability control over the system. Versions 12.2.3 through 12.2.15 are affected.

  • CVE-2026-46935HIGH 7.5

    A vulnerability exists in Oracle's Complex Maintenance, Repair and Overhaul component within Oracle E-Business Suite that allows a low-privileged user with network access to take over the affected system. The flaw is difficult to exploit but has severe consequences—attackers can read, modify, or disable critical maintenance and repair operations. Organizations using versions 12.2.3 through 12.2.15 are at risk and should prioritize assessment and patching.

  • CVE-2026-46958HIGH 7.5

    A vulnerability in Oracle's Subledger Accounting module (part of E-Business Suite) allows a low-privileged network user to gain complete control over the accounting system through a difficult-to-exploit flaw. The attacker would need valid system credentials and network access, but if successful, could read, modify, or delete critical financial data and disrupt operations. This affects Oracle E-Business Suite versions 12.2.3 through 12.2.15.

  • CVE-2026-46959HIGH 7.5

    A vulnerability in Oracle's Subledger Accounting component—part of the E-Business Suite—allows attackers with low-level network access to potentially take over the entire accounting module. While the attack requires special conditions to execute and the attacker must already have basic user credentials, success grants complete control over Subledger Accounting's data and operations. Organizations running versions 12.2.3 through 12.2.15 are at risk.

  • CVE-2026-46966HIGH 7.5

    A vulnerability in Oracle's Universal Work Queue component of E-Business Suite allows a low-privileged user with network access to take over the application. The flaw exists in the site-level administration features and requires specific difficult-to-exploit conditions, but successful compromise results in complete loss of confidentiality, integrity, and availability for the affected system. This affects E-Business Suite versions 12.2.3 through 12.2.15.

  • CVE-2026-46971HIGH 7.5

    Oracle's HR Intelligence system, which is part of Oracle E-Business Suite, contains a security vulnerability that allows a logged-in attacker with network access to take over the application. The flaw affects versions 12.2.3 through 12.2.15. An attacker would need valid user credentials and would need to navigate through some technical obstacles, but successful exploitation grants them complete control over HR Intelligence, potentially exposing or modifying sensitive employee and HR data.

  • CVE-2026-8176HIGH 7.5

    The LatePoint calendar booking plugin for WordPress contains a chain of three separate vulnerabilities that can be combined by an authenticated Agent user to gain full Administrator access. An attacker with Agent-level credentials can manipulate the plugin's functionality to reset an Administrator's password without triggering any Administrator-only security checks, effectively hijacking the WordPress site. This is particularly dangerous because Agent accounts are typically granted to lower-privileged users like appointment schedulers or booking managers—not full site administrators.

  • CVE-2026-46867HIGH 7.2

    Oracle Enterprise Manager Base Platform contains a vulnerability in its Extensibility Framework that allows high-privileged attackers with network access to take over the system. The flaw affects versions 13.5 and 24.1, and exploitation requires HTTPS connectivity but does not need user interaction. A successful attack grants an attacker complete control over the Enterprise Manager platform, including ability to read, modify, or destroy data and disable services.

  • CVE-2026-46922HIGH 7.2

    Oracle HR Intelligence, a component within Oracle E-Business Suite, contains a vulnerability that allows an authenticated high-privileged user with network access to take over the system. The vulnerability affects versions 12.2.3 through 12.2.15 and requires the attacker to already have elevated credentials, meaning it poses a risk primarily from internal threats or from attackers who have compromised privileged accounts. The impact is severe: an attacker could read, modify, or delete sensitive HR data and disrupt the entire HR Intelligence service.

  • CVE-2026-46953HIGH 7.2

    A vulnerability exists in Oracle's HRMS (UK) module within E-Business Suite that allows a privileged network attacker to fully compromise the system. The flaw affects payroll processing for UK organizations running versions 12.2.3 through 12.2.15. An attacker with high-level administrative credentials can exploit this over the network without user interaction, leading to complete takeover of the HRMS system including access to sensitive payroll, employee, and financial data.

  • CVE-2026-46970HIGH 7.2

    Oracle HR Intelligence, a component of Oracle E-Business Suite, contains a vulnerability that allows a privileged network attacker to take control of the system. The flaw affects supported versions 12.2.3 through 12.2.15 and requires the attacker to already have high-level administrative credentials to exploit it. Once exploited, an attacker could compromise confidentiality, integrity, and availability of HR data and system operations.

  • CVE-2026-46914HIGH 7.1

    A flaw in Oracle Solaris 11.4's filesystem component allows an authenticated user on the local system to read sensitive data or crash the operating system. An attacker with standard user privileges can exploit this without needing to interact with the system graphically—it happens automatically through the vulnerable code path. The vulnerability is rated HIGH severity and poses a real risk to organizations running Solaris infrastructure, particularly those handling sensitive data or requiring high availability.

  • CVE-2026-52808HIGH 7.1

    Gogs, an open-source Git hosting platform, contains an authorization bypass vulnerability in three API endpoints that handle repository settings and operations. Write-level collaborators—users with limited repository permissions—can exploit these endpoints to disable critical repository features (issue tracker, wiki) or inject malicious URLs that would compromise other users visiting the repository. The vulnerability exists because these endpoints use weaker permission checks than the equivalent web interface, allowing attackers to escalate their effective privileges within a repository. Gogs 0.14.3 and later patch this issue.

  • CVE-2024-38487HIGH 7.0

    CVE-2024-38487 is a container escape vulnerability affecting api-gateway containers that run with root privileges. An attacker with local access to a system running a vulnerable api-gateway container could break out of the container and gain access to the underlying host system, potentially allowing them to modify, delete, or disable critical services and data. The vulnerability requires local access and some effort to exploit, but the consequences—full host compromise—are severe.

  • CVE-2026-0048MEDIUM 6.8

    A vulnerability exists in Android's WindowState component that allows an attacker to overlay malicious UI on top of legitimate system dialogs, tricking users into granting permissions they did not intend to approve. The attack exploits a tapjacking technique where touch inputs are intercepted and misdirected. No special privileges or user awareness is required for the attack to succeed, making it a local but potentially high-impact privilege escalation vector.

  • CVE-2026-0086MEDIUM 6.8

    A vulnerability in Android's DisableSupervisionActivity allows an attacker to delete supervision data on a device by exploiting a missing null check in the onCreate method. This flaw enables local privilege escalation without requiring any special permissions or user interaction, meaning the exploit could trigger automatically during normal device operation. The vulnerability affects multiple Android versions and has a medium severity rating.

  • CVE-2026-35291MEDIUM 6.6

    Oracle WebLogic Server contains a vulnerability in its Console component that could allow a highly privileged attacker to take over the server if they have network access. The flaw affects versions 14.1.2.0.0 and 15.1.1.0.0 and requires the attacker to already have high-level administrative privileges and overcome additional technical barriers to exploit it. Successful exploitation would give an attacker complete control over the WebLogic Server's data and operations.

  • CVE-2026-12450MEDIUM 6.5

    A flaw in Google Chrome's media handling allows attackers to extract sensitive information from your browser's memory through a specially crafted webpage. An attacker could trick you into visiting a malicious site and potentially access data that shouldn't be exposed—passwords, tokens, or other secrets processed by the browser. This requires user interaction (clicking or visiting the page) but no special permissions, making it a realistic threat for targeted attacks.

  • CVE-2026-50201MEDIUM 6.5

    Steeltoe is a framework for building cloud-native applications. A permissions flaw in its management endpoints allows low-privilege users (like Space Auditors in Cloud Foundry) to access sensitive diagnostic information that should be restricted to higher-trust roles. Specifically, heap dumps, environment variables, and thread dumps are exposed when they shouldn't be, potentially revealing application secrets and configuration details. Fixed versions are available.

  • CVE-2025-9912MEDIUM 6.3

    CVE-2025-9912 is a local privilege escalation flaw in Nokia SR Linux that allows an authenticated user with elevated privileges to execute arbitrary commands as root. The vulnerability requires local access and existing authentication—an insider or someone already on the system—but once triggered, can grant complete system control. This is not a remote attack vector; however, it does transform limited user accounts into fully privileged ones.

  • CVE-2026-10217MEDIUM 6.3

    A privilege management flaw exists in nextlevelbuilder GoClaw versions up to 3.11.3 that allows authenticated users to escalate their access or perform unauthorized actions. The vulnerability affects the RoleAdmin Gateway component, specifically in how it handles configuration saves. An attacker with valid credentials can exploit this remotely to gain elevated permissions or manipulate role-based access controls, potentially affecting data confidentiality, integrity, and availability.

  • CVE-2026-11308MEDIUM 6.3

    CVE-2026-11308 is a privilege escalation vulnerability in Google Chrome's extension system that allows an attacker to gain elevated permissions on a user's system. The attack requires social engineering—convincing a user to install a malicious browser extension—but once installed, the flaw in how Chrome enforces extension permissions allows the attacker to break out of the extension sandbox and perform actions at a higher privilege level than the extension should be allowed. This affects Windows, macOS, and Linux systems running Chrome versions prior to 149.0.7827.53.

  • CVE-2026-0046MEDIUM 6.2

    CVE-2026-0046 is a local privilege escalation vulnerability affecting Google Android that exploits a weakness in the InputInterceptor component of Letterbox.java. An attacker can overlay malicious UI elements on top of legitimate permission prompts, tricking users into granting permissions they did not intend to approve. What makes this particularly concerning is that exploitation requires no special system privileges and occurs without user awareness—the victim merely sees what appears to be a normal permission dialog. The result is unauthorized elevation of the attacker's application privileges within the Android system.

  • CVE-2026-0055MEDIUM 6.2

    A path traversal vulnerability in Android's PackageInstallerService allows an attacker to write a Device Policy Controller (DPC) application to an unintended directory. By exploiting this flaw, an unprivileged local process can escalate its privileges without requiring user interaction or additional system permissions. The vulnerability affects multiple Android versions and could allow an attacker with local access to gain elevated capabilities on the device.

  • CVE-2026-11229MEDIUM 6.1

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the application handles certain enterprise features that could allow someone with physical access to your device to gain elevated privileges. The vulnerability requires an attacker to be present at the machine itself and does not need you to take any action—they can exploit it directly. This is a local-only threat and cannot be exploited remotely over the internet.

  • CVE-2026-20246MEDIUM 6.0

    Cisco Umbrella Virtual Appliance contains a privilege escalation flaw in its vmadmin command-line interface. An authenticated attacker with vmadmin-level access can run specially crafted commands to gain full root privileges on the device. The vulnerability stems from insufficient input validation and requires local access and existing elevated privileges to exploit, limiting its immediate blast radius but creating a critical post-compromise risk for affected deployments.

  • CVE-2026-46877MEDIUM 6.0

    A vulnerability in Oracle VM VirtualBox version 7.2.8 allows an administrator or highly privileged user on the host system to read sensitive data from the virtual machine. The flaw is in the VMSVGA graphics device component. An attacker would need administrative-level access to the infrastructure running VirtualBox, but from that position can extract confidential information that VirtualBox can access. The vulnerability does not enable attackers to modify or delete data, nor does it crash the system.

  • CVE-2026-48210MEDIUM 5.7

    OTRS 2026.3.1 has a configuration issue where ticket forwarding automatically marks internal information as visible to customers, and administrators cannot turn this off through the user interface. This means sensitive ticket details that should remain internal can unintentionally become visible to external customers, creating a data leakage risk.

  • CVE-2026-44119MEDIUM 5.5

    Apache HTTP Server versions 2.4.67 and earlier contain a privilege escalation vulnerability that allows local users who can author .htaccess files to read arbitrary files with the permissions of the httpd daemon user. This is a local-only vulnerability requiring existing system access and the ability to modify .htaccess configuration files, but it can expose sensitive application data and system files to unprivileged users.

  • CVE-2026-11276MEDIUM 5.1

    Google Chrome versions before 149.0.7827.53 contain a flaw in how the Cast feature (which enables screen mirroring and media streaming to nearby devices) processes network traffic. An attacker physically present on the same local network can send specially crafted traffic to bypass access controls that would normally prevent unauthorized casting operations. This is a local network attack that doesn't require user interaction but is limited in scope—it cannot crash systems or execute arbitrary code, only manipulate casting permissions.

  • CVE-2026-50565MEDIUM 4.9

    Fission, an open-source serverless framework for Kubernetes, had a configuration flaw in versions before 1.24.0 where builder pods automatically mounted sensitive service account credentials into user-supplied container images. This meant anyone deploying a function through Fission could potentially access the credentials needed to interact with your Kubernetes cluster, such as listing resources or reading secrets. The issue stems from Kubernetes' default behavior of auto-mounting service account tokens unless explicitly disabled—Fission wasn't disabling this protection for builder pods. The flaw has been patched in version 1.24.0.

  • CVE-2026-12313MEDIUM 4.7

    A vulnerability in Firefox and Thunderbird's process sandboxing mechanism allows an attacker to leak sensitive information and potentially escape the sandbox through a crafted webpage or message. The attack requires user interaction (such as visiting a malicious site or opening a specially prepared message) and affects your system's security boundary—the sandbox that isolates the browser process from the rest of your computer. Mozilla has patched this in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-54319MEDIUM 4.2

    Daytona, a runtime platform for executing AI-generated code and agent workflows, contains a path-traversal vulnerability in versions prior to 0.186. When users specify a volume identifier to mount storage, the system failed to properly validate the path, potentially allowing an authenticated user to reference storage locations outside the intended directories. An attacker with valid credentials could craft a specially formatted volume reference to access or modify files beyond the sandbox's intended scope.

  • CVE-2026-56212LOW 3.8

    Capgo versions before 12.128.2 contain a flaw in how they enforce two-factor authentication policies. A team or organization administrator can mandate that all team members use two-factor authentication, but the system doesn't check whether the administrator themselves has 2FA enabled first. This creates a gap where security policy enforcement becomes inconsistent and opens the door to administrative misuse—an admin could lock team members out of their accounts by enforcing a security requirement they haven't met themselves.

  • CVE-2026-0016LOW 3.3

    A permissions validation flaw in Android's credential management system allows a local attacker with limited user privileges to read sensitive information across other user accounts without special permissions or user interaction. The vulnerability resides in how the system handles credential provider updates when services are removed, creating a bypass that exposes data intended to be isolated between users.

  • CVE-2026-0050LOW 3.3

    CVE-2026-0050 is a local information disclosure vulnerability in Android's Bluetooth adapter service. A malicious app with basic user-level permissions can bypass security checks in the handleBondStateChanged function to read sensitive Bluetooth-related information without requiring additional privileges or user interaction. The impact is limited to information disclosure; the attacker cannot modify data or crash the system.

  • CVE-2026-28586LOW 3.3

    CVE-2026-28586 is a local information disclosure vulnerability in Android's AppOpsService that allows an already-authenticated user to bypass permission checks and read sensitive data they shouldn't have access to. The flaw requires the attacker to already have a local account on the device; there's no way to exploit it remotely. The exposure is classified as low-severity because the data leaked is limited and no system functions are disrupted.