Vulnerabilities (CVE)

Filtered by CWE-269
Total 3403 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-60890 1 Oracle 1 Payroll 2026-08-12 N/A 8.8 HIGH
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2021-20021 2 Microsoft, Sonicwall 20 Windows, Email Security, Email Security Appliance 3300 and 17 more 2026-08-12 7.5 HIGH 9.8 CRITICAL
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2019-1405 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1709 and 12 more 2026-08-12 7.2 HIGH 7.8 HIGH
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
CVE-2022-20759 1 Cisco 2 Adaptive Security Appliance Software, Secure Firewall Threat Defense 2026-08-11 8.5 HIGH 8.8 HIGH
A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15. This vulnerability is due to improper separation of authentication and authorization scopes. An attacker could exploit this vulnerability by sending crafted HTTPS messages to the web services interface of an affected device. A successful exploit could allow the attacker to gain privilege level 15 access to the web management interface of the device. This includes privilege level 15 access to the device using management tools like the Cisco Adaptive Security Device Manager (ASDM) or the Cisco Security Manager (CSM). Note: With Cisco FTD Software, the impact is lower than the CVSS score suggests because the affected web management interface allows for read access only.
CVE-2024-45496 2026-08-11 N/A 9.9 CRITICAL
A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to the node. An attacker with developer-level access can provide a crafted .gitconfig file containing commands executed during the cloning process, leading to arbitrary command execution on the worker node. An attacker running code in a privileged container could escalate their permissions on the node running the container.
CVE-2025-4334 1 Najeebmedia 1 Memberhero 2026-08-11 N/A 9.8 CRITICAL
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated attackers to register as an administrator.
CVE-2024-38014 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2026-08-10 N/A 7.8 HIGH
Windows Installer Elevation of Privilege Vulnerability
CVE-2024-37980 1 Microsoft 4 Sql Server 2016, Sql Server 2017, Sql Server 2019 and 1 more 2026-08-10 N/A 8.8 HIGH
Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2021-40447 1 Microsoft 9 Windows 10, Windows 7, Windows 8.1 and 6 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-38671 1 Microsoft 9 Windows 10, Windows 7, Windows 8.1 and 6 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-38667 1 Microsoft 9 Windows 10, Windows 7, Windows 8.1 and 6 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-38639 1 Microsoft 9 Windows 10, Windows 7, Windows 8.1 and 6 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Win32k Elevation of Privilege Vulnerability
CVE-2021-38638 1 Microsoft 9 Windows 10, Windows 7, Windows 8.1 and 6 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2021-38634 1 Microsoft 4 Windows 10, Windows Server 2016, Windows Server 2019 and 1 more 2026-08-10 7.2 HIGH 7.1 HIGH
Microsoft Windows Update Client Elevation of Privilege Vulnerability
CVE-2021-38633 1 Microsoft 9 Windows 10, Windows 7, Windows 8.1 and 6 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-38630 1 Microsoft 9 Windows 10, Windows 7, Windows 8.1 and 6 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-38628 1 Microsoft 9 Windows 10, Windows 7, Windows 8.1 and 6 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2021-38626 1 Microsoft 1 Windows Server 2008 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-38625 1 Microsoft 1 Windows Server 2008 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Kernel Elevation of Privilege Vulnerability
CVE-2021-36975 1 Microsoft 4 Windows 10, Windows Server 2016, Windows Server 2019 and 1 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Win32k Elevation of Privilege Vulnerability