The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,089 vulnerabilities with CWE-269
CVE-2026-65835
MEDIUM
Capsule >= 0.13.0, < 0.13.8 - Cross-Tenant Cluster-Scoped Resource Creation
CVSS 6.6
CVE-2026-14980
HIGH
IBM WebSphere Application Server Liberty is affected by a cross-site request forgery
CVSS 8.3
CVE-2026-12687
HIGH
ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group ID
CVSS 7.5
CVE-2026-17969
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-17956
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-17952
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 7.5
CVE-2026-17950
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-17877
HIGH
Google Chrome - Privilege Escalation
CVSS 8.4
CVE-2026-17868
HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-17864
HIGH
Google Chrome - Privilege Escalation
CVSS 7.8
CVE-2026-17863
HIGH
Google Chrome - Privilege Escalation
CVSS 7.8
CVE-2026-17816
HIGH
Google Chrome - Privilege Escalation
CVSS 7.5
CVE-2026-17751
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-17744
HIGH
Google Chrome < 151.0.7922.72 - Sandbox Escape via File Input Inappropriate Implementation on Linux
CVSS 7.1
CVE-2026-12144
HIGH
Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escalation via 'user_role_set' Parameter
CVSS 8.8
CVE-2026-18107
HIGH
Criu: criu: container escape via rseq critical section hijack during checkpoint/restore
CVSS 7.8
CVE-2026-15992
HIGH
WP Password Policy <= 3.7.1 - Authenticated (Subscriber+) Privilege Escalation
CVSS 8.8
CVE-2026-14328
HIGH
Eazy Plugin Manager <= 4.4.1 - Authenticated (Subscriber+) Privilege Escalation via pos_get_option AJAX Action and admin/login REST Endpoint
CVSS 8.8
CVE-2026-14545
CRITICAL
TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset
CVSS 9.8
CVE-2026-66015
HIGH
JFrog Platform contains an authorization flaw that may allow authenticated privilege escalation.
CVSS 7.2
CVE-2026-66399
MEDIUM
phpMyFAQ before 4.1.6 Privilege Escalation via Group Membership
CVSS 6.5
CVE-2026-13152
HIGH
Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation
CVSS 8.1
CVE-2026-12394
CRITICAL
MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator
CVSS 9.8
CVE-2026-12502
HIGH
Loytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo
CVE-2026-16743
MEDIUM
Accountsservice: accountsservice: arbitrary file read via seticonfile for systemd-homed users
CVSS 5.5
Details
Vulnerabilities
3,089
Exploit Likelihood
Medium