<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Privilege Escalation</title>
  <link>https://cvedaily.com/pages/tags/priv-esc.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/priv-esc.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Privilege Escalation</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:26 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-50033 – Local privilege escalation due to DLL hijacking vulnerability. The following pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-50033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-50033</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-50033</strong></p>
  <p>Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44682 – Local privilege escalation due to DLL hijacking vulnerability. The following pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44682</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44682</strong></p>
  <p>Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44609 – Local privilege escalation due to EXE hijacking vulnerability. The following pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44609</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44609</strong></p>
  <p>Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42061 – Local privilege escalation due to excessive permissions assigned to child proces...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42061</guid>
    <pubDate>Wed, 03 Jun 2026 20:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42061</strong></p>
  <p>Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15656 – Incorrect Privilege Assignment vulnerability in Mojoomla School Management allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15656</guid>
    <pubDate>Wed, 03 Jun 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15656</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation.  This issue affects School Management: from n/a through 93.2.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4481 – Dräger Protector Software prior to version 6.4.2 contains a local privilege esca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4481</guid>
    <pubDate>Tue, 02 Jun 2026 22:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4481</strong></p>
  <p>Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-4480 – Dräger Protector Software prior to version 6.4.2 contains a local privilege esca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4480</guid>
    <pubDate>Tue, 02 Jun 2026 22:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-4480</strong></p>
  <p>Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8036 – Improper input validation in NI-PAL may allow a local authenticated user to acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8036</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8036</strong></p>
  <p>Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64390 – A privilege escalation vulnerability exists in PlayStation 4 firmware versions 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64390</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64390</strong></p>
  <p>A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Disc Java) sandbox can be escaped through a malformed JAR file.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40715 – Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40715</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40715</strong></p>
  <p>Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-53209 – Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53209</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-53209</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation.  This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8206 – The Kirki – Freeform Page Builder, Website Builder &amp; Customizer plugin for WordP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8206</guid>
    <pubDate>Tue, 02 Jun 2026 04:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8206</strong></p>
  <p>The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registere…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25718 – Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25718</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25718</strong></p>
  <p>Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk mode and access the underlying operating system through a specific dialog interaction. Attackers can exploit this kiosk escape to take control of the operating system and cause the device to display incorrect or no information from the connected Delta Family patient monitor.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49134 – CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49134</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49134</strong></p>
  <p>CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in temporary file handling. The installer creates a temporary file with mktemp, writes a privileged shell payload into it, and executes it with administrator privileges via bash, allowing a same-user local proc…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45275 – Nextcloud is an open source content collaboration platform. Prior to version 2.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45275</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45275</strong></p>
  <p>Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. This results in an authorization bypass and privilege escalation, allowing unauthorized distribution of restricted files. This issue has been patched in…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41013 – Input validation bypass in SMB volume mount handling in CloudFoundry Foundation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41013</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41013</strong></p>
  <p>Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells.  Affected versions: smb-volume-release: All versions prior to v3.60.0 CF Deployment: All…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-22872 – Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22872</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-22872</strong></p>
  <p>Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the namespace, this is ineffective for cluster-scoped resources. Prior to version 0.13.0, tenant administrators can leverage the Controller's elevated privileges to create cluster-scoped resources (such…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48879 – Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Esc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48879</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48879</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation.  This issue affects AIWU: from n/a through 1.4.17.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42680 – Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGaller...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42680</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42680</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation.  This issue affects Contest Gallery Pro: from n/a through 29.0.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10532 – Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10532</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10532</strong></p>
  <p>Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.  More precisely, an attacker able to influence serialized data sent to  SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects.   Although deserialization is heavily restricted by HardenedObjec…</p>
  <p><strong>CVSS:</strong> 2.9 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9051 – There is an authentication bypass vulnerability in the NI SystemLink Enterprise ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9051</guid>
    <pubDate>Fri, 29 May 2026 19:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9051</strong></p>
  <p>There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to privilege escalation or information disclosure.  Successful exploitation requires an attacker to send a specially crafted HTTP request.  This vulnerability affects NI SystemLink Enterprise 2026-04 and p…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44962 – Plesk contains an XPath injection vulnerability in the APS Application Catalog s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44962</guid>
    <pubDate>Fri, 29 May 2026 16:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44962</strong></p>
  <p>Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This allows an authenticated, low-privileged user to execute arbitrary operating system commands on the server, resulting in local privilege escalation.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-643</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32906 – OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32906</guid>
    <pubDate>Fri, 29 May 2026 16:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32906</strong></p>
  <p>OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. Attackers with limited exec approval permissions can bypass intended approval splits to approve plugin actions outside operator configuration.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45043 – RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45043</guid>
    <pubDate>Fri, 29 May 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45043</strong></p>
  <p>RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create service accounts under arbitrary parent identities, including the root user (minioadmin). The endpoint accepts attacker-controlled parent, claims, accessKey, and secretKey values without enforcing privi…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8732 – The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8732</guid>
    <pubDate>Fri, 29 May 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8732</strong></p>
  <p>The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the non…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8809 – The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8809</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8809</guid>
    <pubDate>Thu, 28 May 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8809</strong></p>
  <p>The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with no authentication or integrity verification — to select a cleanup branch that si…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8809">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5343 – Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5343</guid>
    <pubDate>Thu, 28 May 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5343</strong></p>
  <p>Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation.  This issue affects SAML SSO - Service Provider: from 0.0.0 before 3.1.4.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-49095 – Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49095</guid>
    <pubDate>Thu, 28 May 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-49095</strong></p>
  <p>Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent policy configuration by injecting values into a configuration override mechanism that is not adequately validated. An attacker can cause Elastic Agents to be issued API keys with elevated Elasticsearch…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9094 – Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-orga...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9094</guid>
    <pubDate>Thu, 28 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9094</strong></p>
  <p>Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-9828 – Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9828</guid>
    <pubDate>Thu, 28 May 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-9828</strong></p>
  <p>Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted.  More precisely, an attacker able to influence serialized data sent to  SimpleSocketServer or SimpleSSLSocketServer can instantiate objects from  classes in the java.lang and java.util packages that are not explic…</p>
  <p><strong>CVSS:</strong> 2.9 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8980 – The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privile...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8980</guid>
    <pubDate>Thu, 28 May 2026 14:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8980</strong></p>
  <p>The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) and manufacturer accounts via crafted POST requests.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49237 – An issue was discovered in Canonical Multipass for macOS before version 1.16.3 d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49237</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49237</guid>
    <pubDate>Thu, 28 May 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49237</strong></p>
  <p>An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd daemon binary to root:wheel, five co-located binaries (multipass, qemu-img, qemu-system-aarch64, qemu-system-x86_64, and sshfs_server) in /Library/Application Support/com.canonical.multipass/bin/ retain…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49237">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6226 – The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6226</guid>
    <pubDate>Thu, 28 May 2026 09:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6226</strong></p>
  <p>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary form definitions from user input instead of securely loading them from the backend. When $_POST['_acf_form'] is an array (rather than a form ID), the validate_form() function bypa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9802 – A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9802</guid>
    <pubDate>Thu, 28 May 2026 06:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9802</strong></p>
  <p>A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been revoked. Successful exploitation grants the attacker unauthorized access to the victim's account, potenti…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9795 – A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9795</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9795</guid>
    <pubDate>Thu, 28 May 2026 05:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9795</strong></p>
  <p>A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scope mapping. This bypasses intended security controls, allowing the injected role to be projected into a user's authentication token when they access t…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9795">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32996 – This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privile...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32996</guid>
    <pubDate>Thu, 28 May 2026 05:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32996</strong></p>
  <p>This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9789 – A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense softwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9789</guid>
    <pubDate>Thu, 28 May 2026 03:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9789</strong></p>
  <p>A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the service does not check the caller's privileges before running file deletion comm…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48150 – Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/ro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48150</guid>
    <pubDate>Wed, 27 May 2026 18:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48150</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAdmin middleware, which passes any user who is a builder for the app id in the x-budibase-app-id header. That check admits both global builders and workspace-scoped builders (builder.apps set but builder.global unset). The controller then spreads the request body into the SDK call…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45716 – Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/glo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45716</guid>
    <pubDate>Wed, 27 May 2026 18:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45716</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user with builder permissions to access it. When SMTP email is not configured (the default for self-hosted Budibase instances), this endpoint bypasses the admin-restricted invite flow and directly creates users via bulkCreate,…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68712 – SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68712</guid>
    <pubDate>Wed, 27 May 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68712</strong></p>
  <p>SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authentication. By navigating cascading interface flows - insecure navigation through exposed routes facilitat…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9704 – A flaw was found in Keycloak. An authenticated user with low privileges can expl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9704</guid>
    <pubDate>Wed, 27 May 2026 14:17:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9704</strong></p>
  <p>A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client credentials. This allows the user to gain the permissions of the client's service account, leading to…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42758 – Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias Webinar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42758</guid>
    <pubDate>Wed, 27 May 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42758</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42731 – Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verifi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42731</guid>
    <pubDate>Wed, 27 May 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42731</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41670 – A local user with low privileges may be able to influence the behavior of a priv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41670</guid>
    <pubDate>Wed, 27 May 2026 08:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41670</strong></p>
  <p>A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not sufficiently protected against modification by low-privileged users. As the service runs with elevated privileges, successfu…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8787 – The Firebase Support &amp; Chat Management plugin for WordPress is vulnerable to pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8787</guid>
    <pubDate>Wed, 27 May 2026 07:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8787</strong></p>
  <p>The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due to the `firebase_auth()` function authenticating the request as the WordPress user whose email is supplied in the `user_email` POST parameter without verifying ownership of that email (no Firebase ID token signature/issuer/audience verification…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46284 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46284</guid>
    <pubDate>Tue, 26 May 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46284</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43306 – A logic issue was addressed with improved checks. This issue is fixed in macOS S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43306</guid>
    <pubDate>Tue, 26 May 2026 22:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43306</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-68711 – AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68711</guid>
    <pubDate>Tue, 26 May 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-68711</strong></p>
  <p>AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E]…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-68708 – SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68708</guid>
    <pubDate>Tue, 26 May 2026 21:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-68708</strong></p>
  <p>SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via advertisement or browser intent…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-68710 – Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68710</guid>
    <pubDate>Tue, 26 May 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-68710</strong></p>
  <p>Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes facilitates app control evasion {I.N.T.E.R.F.A.C.E] via…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68709 – SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68709</guid>
    <pubDate>Tue, 26 May 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68709</strong></p>
  <p>SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. This unsafe navigation path results in script execution and may allow UI spoofing or privilege escalation.</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9560 – Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9560</guid>
    <pubDate>Tue, 26 May 2026 18:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9560</strong></p>
  <p>Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48899 – An improper access check allows privilege escalation through the com_users batch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48899</guid>
    <pubDate>Tue, 26 May 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48899</strong></p>
  <p>An improper access check allows privilege escalation through the com_users batch task.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48898 – An improper access check allows privilege escalation through the com_users batch...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48898</guid>
    <pubDate>Tue, 26 May 2026 17:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48898</strong></p>
  <p>An improper access check allows privilege escalation through the com_users batch task.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25112 – A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25112</guid>
    <pubDate>Tue, 26 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25112</strong></p>
  <p>A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44469 – The affected product extracts installation files to a temporary directory with i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44469</guid>
    <pubDate>Tue, 26 May 2026 08:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44469</strong></p>
  <p>The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44468 – The affected product creates a directory with insecure default permissions durin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44468</guid>
    <pubDate>Tue, 26 May 2026 08:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44468</strong></p>
  <p>The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45216 – Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45216</guid>
    <pubDate>Mon, 25 May 2026 23:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45216</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation.  This issue affects Smart Manager: from n/a through 8.85.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48845 – In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48845</guid>
    <pubDate>Mon, 25 May 2026 20:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48845</strong></p>
  <p>In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9489 – NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9489</guid>
    <pubDate>Mon, 25 May 2026 02:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9489</strong></p>
  <p>NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging t…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6895 – The WishList Member plugin for WordPress is vulnerable to Missing Authorization ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6895</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6895</strong></p>
  <p>The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to the attacker in the AJAX JSON response. An attacker who obtains this key can auth…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6419 – The WishList Member plugin for WordPress is vulnerable to Privilege Escalation v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6419</guid>
    <pubDate>Sat, 23 May 2026 05:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6419</strong></p>
  <p>The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to supply an arbitrary admin screen identifier via the data[url] paramete…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40172 – authentik is an open-source identity provider. In versions prior to 2025.12.5 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40172</guid>
    <pubDate>Fri, 22 May 2026 19:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40172</strong></p>
  <p>authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, without requiring enable_group_superuser, leading to privilege escalation. This bypasses the stricter per…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28445 – Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28445</guid>
    <pubDate>Fri, 22 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28445</strong></p>
  <p>Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg field directly via Solid's innerHTML directive without any sanitization, even though DOMPurify is already a dependency and is used elsewhere in the codebase (e.g., StreamingBubble.tsx). Because rating blocks are not flagged as isUnsafe by the…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-39821 – The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39821</guid>
    <pubDate>Fri, 22 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-39821</strong></p>
  <p>The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "exam…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-1289</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8353 – Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8353</guid>
    <pubDate>Fri, 22 May 2026 15:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8353</strong></p>
  <p>Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inject arbitrary JavaScript that executes in the context of any authenticated user visiting the affected account pages. This can lead to session hijacking, credential theft, malicious actions performed on behalf of users, and potential privilege escalation. The Concrete CMS security…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32747 – Dell PowerFlex Manager, version(s) &lt;=4.6.2, contain(s) an Incorrect Privilege As...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32747</guid>
    <pubDate>Fri, 22 May 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32747</strong></p>
  <p>Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9018 – The Easy Elements for Elementor – Addons &amp; Website Templates plugin for WordPres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9018</guid>
    <pubDate>Fri, 22 May 2026 05:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9018</strong></p>
  <p>The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_nopriv_eel_register` AJAX handler iterating the attacker-controlled `custom_meta` POST array and writing every supplied key-value pair to the newly created user's…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8350 – Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8350</guid>
    <pubDate>Thu, 21 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8350</strong></p>
  <p>Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group. Any authenticated user with access to the bulk user assignment dashboard page can add any user email to any group and can remove legitimate admins. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 7.5 with v…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47101 – LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API key...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47101</guid>
    <pubDate>Thu, 21 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47101</strong></p>
  <p>LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created with access to admin-only routes can then be used to reach those routes successfully, bypassing the role-b…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5118 – The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5118</guid>
    <pubDate>Thu, 21 May 2026 13:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5118</strong></p>
  <p>The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This makes it possible for unauthenticated attackers to create administrator accounts b…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-48172 – LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48172</guid>
    <pubDate>Thu, 21 May 2026 02:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-48172</strong></p>
  <p>LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been hit with exploitation of the vulnerability. If there is output, we recommend yo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29518 – Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29518</guid>
    <pubDate>Wed, 20 May 2026 13:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29518</strong></p>
  <p>Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitiv…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7467 – The Read More &amp; Accordion plugin for WordPress is vulnerable to Privilege Escala...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7467</guid>
    <pubDate>Wed, 20 May 2026 02:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7467</strong></p>
  <p>The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting which database tables can be written to during import and not properly validating the imported data. This makes it possible for authenticated attackers, with permission granted by the site owner thro…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7284 – The Easy Elements for Elementor – Addons &amp; Website Templates plugin for WordPres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7284</guid>
    <pubDate>Wed, 20 May 2026 02:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7284</strong></p>
  <p>The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.4.4. This is due to the 'easyel_handle_register' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during regist…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6456 – The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6456</guid>
    <pubDate>Wed, 20 May 2026 02:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6456</strong></p>
  <p>The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` REST API endpoint using a loose comparison (`!=` instead of `!==`) for secret validation at `app/RestAPI.php:111`, combined with no validation that the secret is non-empty. When a target user has never used the "Remember me" feature, their…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34390 – Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34390</guid>
    <pubDate>Tue, 19 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34390</strong></p>
  <p>Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vulnerability where insufficient access control checks in ProjectUsersAddCommand (manage_proj_user_add.php) allow users having manage_project_threshold access level (manager by default) to grant project-level administrator access to any user (including themselves) in any Project th…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34358 – CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34358</guid>
    <pubDate>Tue, 19 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34358</strong></p>
  <p>CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access control vulnerability where multiple admin controllers enforce permission checks on form display methods but omit equivalent checks on the corresponding write methods, allowing any authenticated user to bypass RBAC via direct POST/PATCH requests. Controllers missing checks on write m…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34246 – CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34246</guid>
    <pubDate>Tue, 19 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34246</strong></p>
  <p>CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability exists in the admin role management interface. In app/Http/Controllers/Admin/RoleController.php, the datatable() method interpolates $role->name and $role->color directly into a <span> element's HTML and style attribute without sanitization, and the c…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8370 – Execution with unnecessary privileges vulnerability in Broadcom Automic Automati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8370</guid>
    <pubDate>Tue, 19 May 2026 19:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8370</strong></p>
  <p>Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64, Solaris Sparc 64 allows Privilege Escalation, Target Programs with Elevated Privileges.  This issue affects Automic Automation: < 24.4.4 HF1.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30118 – scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30118</guid>
    <pubDate>Tue, 19 May 2026 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30118</strong></p>
  <p>scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers to force the backend server to send HTTP requests to attacker-controlled URLs, leading to authentication cookies and headers exposure and possible privilege escalation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8972 – Privilege escalation in the WebRTC: Audio/Video component. This vulnerability wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8972</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8972</strong></p>
  <p>Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8970 – Privilege escalation in the Security component. This vulnerability was fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8970</guid>
    <pubDate>Tue, 19 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8970</strong></p>
  <p>Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8957 – Privilege escalation in the Enterprise Policies component. This vulnerability wa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8957</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8957</strong></p>
  <p>Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8955 – Privilege escalation in the DOM: Workers component. This vulnerability was fixed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8955</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8955</strong></p>
  <p>Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8952 – Privilege escalation in the Application Update component. This vulnerability was...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8952</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8952</strong></p>
  <p>Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22069 – A local privilege escalation vulnerability exists in O+ Connect because it fails...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22069</guid>
    <pubDate>Tue, 19 May 2026 04:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22069</strong></p>
  <p>A local privilege escalation vulnerability exists in O+ Connect because it fails to validate the identity of the caller on the pipe interface.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22069">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32323 – Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32323</guid>
    <pubDate>Tue, 19 May 2026 02:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32323</strong></p>
  <p>Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escalation during installation or upgrade. The installer package executes binaries from /Applications/Mullvad VPN.app without verifying if the bundle is attacker-controlled or that the path is the legitimate Mullvad application. A user in the admin group c…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41085 – Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41085</guid>
    <pubDate>Mon, 18 May 2026 17:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41085</strong></p>
  <p>Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrator-level privileges through exploitation of specific system interfaces.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4320 – Authorization Bypass vulnerability in Creartia's ICMS software could allow an at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4320</guid>
    <pubDate>Mon, 18 May 2026 11:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4320</strong></p>
  <p>Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of the login process, causing the script to continue running and enabling privilege escalation without the need for credentials.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8719 – The AI Engine – The Chatbot, AI Framework &amp; MCP for WordPress plugin for WordPre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8719</guid>
    <pubDate>Sun, 17 May 2026 04:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8719</strong></p>
  <p>The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscrib…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45665 – Open WebUI is a self-hosted artificial intelligence platform designed to operate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45665</guid>
    <pubDate>Fri, 15 May 2026 22:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45665</strong></p>
  <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due to an improper sanitization order (specifically, DOMPurify is executed before the marked library). This vulnerability allows a compromised or malicious administrator to plant a malicious payload in t…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6228 – The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6228</guid>
    <pubDate>Fri, 15 May 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6228</strong></p>
  <p>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient authorization checks in the role field update mechanism combined with overly permissive capabilities for the admin_form post type. The admin_form custom post type uses 'capability_type' => 'page', which grants editors the ability to creat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54518 – Improper isolation of shared resources within the CPU operation cache on Zen 2-b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54518</guid>
    <pubDate>Fri, 15 May 2026 05:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54518</strong></p>
  <p>Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-1189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36333 – A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36333</guid>
    <pubDate>Fri, 15 May 2026 05:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36333</strong></p>
  <p>A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7373 – Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7373</guid>
    <pubDate>Fri, 15 May 2026 03:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7373</strong></p>
  <p>Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When started the metasploitPostgreSQL service would start the postgres.exe child process which would in turn load an OpenSSL configuration file from a static location. This static location would be writable by a pre-existing "vagrant" user, if they already…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-29936 – Improper input validation within the AMD Platform Management Framework (PMF) cou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29936</guid>
    <pubDate>Fri, 15 May 2026 03:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-29936</strong></p>
  <p>Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or allowing privilege escalation resulting in loss of confidentiality.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21962 – Improper Input Validation in the AMD RAID driver could allow an attacker to poin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21962</guid>
    <pubDate>Fri, 15 May 2026 03:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21962</strong></p>
  <p>Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-1220</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0432 – Incorrect default permissions in the installation directory for the AMD chipset ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0432</guid>
    <pubDate>Fri, 15 May 2026 02:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0432</strong></p>
  <p>Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52540 – An improper input validation vulnerability within the AMD Platform Management Fr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52540</guid>
    <pubDate>Fri, 15 May 2026 02:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52540</strong></p>
  <p>An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52540">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
