The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
3,089 vulnerabilities with CWE-269
CVE-2026-10610
HIGH
Local privilege escalation in ESET security applications for macOS
CVE-2026-7483
HIGH
Local privilege escalation in ESET security applications for macOS
CVE-2026-12981
HIGH
CAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password Reset
CVSS 7.5
CVE-2026-12497
HIGH
ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection
CVSS 7.5
CVE-2026-12736
HIGH
WPify Woo <= 5.4.16 - Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint
CVSS 8.0
CVE-2026-16764
MEDIUM
OWASP DefectDojo API/Web serializers.py UserSerializer privileges management
CVSS 6.3
CVE-2026-38764
HIGH
Protegent 360 2.0.0.4 - Local Privilege Escalation via pgsecdl.sys Kernel Driver
CVSS 7.8
CVE-2026-34496
HIGH
victor Web - Priviledge Escalation
CVE-2026-15630
CRITICAL
Casdoor < v3.115.0 - Authenticated Cross-Tenant Resource Manipulation via ID Parameter Mismatch
CVSS 9.9
CVE-2026-65897
HIGH
Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups
CVSS 8.8
CVE-2026-15017
HIGH
MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers
CVSS 8.8
CVE-2026-61246
HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60455
HIGH
Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 Auth RCE via Thirdparty Jars
CVSS 8.8
CVE-2026-60439
HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60373
HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via HTTP
CVSS 8.8
CVE-2026-60372
CRITICAL
Oracle Platform Security for Java 12.2.1.4.0/14.1.2.0.0 - Unauth RCE via Thirdparty Jars
CVSS 9.8
CVE-2026-60371
HIGH
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Authenticated Remote Takeover via Physical Network Access
CVSS 8.0
CVE-2026-60369
CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Remote Code Execution via Centralized Thirdparty Jars
CVSS 9.9
CVE-2026-60367
CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 9.8
CVE-2026-60366
CRITICAL
Oracle Platform Security for Java 12.2.1.4.0, 14.1.2.0.0 - Unauthenticated Remote Code Execution via HTTP
CVSS 10.0
CVE-2026-38766
HIGH
Protegent 360 2.0.0.4 - Local Privilege Escalation via sub_186f4 Function
CVSS 7.8
CVE-2026-38765
HIGH
Protegent 360 2.0.0.4 - Local Privilege Escalation via pgsecdl.sys Kernel Driver
CVSS 7.8
CVE-2026-16607
HIGH
Authenticated local root privilege escalation vulnerability in openFT for Linux and Oracle Solaris
CVSS 7.8
CVE-2026-62145
HIGH
checkpoint Quantum Security Gateway - Local Privilege Escalation in Gaia Portal
CVSS 7.5
CVE-2026-65603
HIGH
Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update
CVSS 8.8
Details
Vulnerabilities
3,089
Exploit Likelihood
Medium