Privilege Escalation

Privilege Escalation vulnerabilities allow an attacker to gain elevated access rights beyond their authorized level. This can enable unauthorized access to sensitive resources and system functions.

Total CVEs

49

Typical Severity

HIGH

Category

General

Understanding Privilege Escalation

Detailed information about this vulnerability type.

How to Identify

  • Review security advisories
  • Perform regular security testing

Prevention Best Practices

  • Follow security best practices
  • Keep systems updated

Privilege Escalation CVEs (49)

DescriptionVendor / ProductExploit Status
CVE-2026-27829.8

This critical vulnerability allows an attacker to gain higher access privileges within Firefox and Thunderbird, potentially letting them execute harmful actions on a user's system. It affects versions prior to 148 for Firefox and Thunderbird, meaning users need to update their software to stay protected.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27809.8

This critical vulnerability allows an attacker to gain higher privileges within Firefox or Thunderbird, potentially letting them execute harmful actions on the user's system. It affects versions prior to 148 for Firefox and Thunderbird, and requires the attacker to exploit the Netmonitor component to take advantage of this flaw.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2026-27779.8

This vulnerability allows an attacker to gain higher access privileges within the messaging system of Firefox and Thunderbird, potentially letting them execute harmful actions on the user's system. It affects specific versions of these applications, so users running outdated software are at greater risk.

mozillafirefox
Exploit Available
about 1 month agoFeb 24, 2026
CVE-2025-639467.4

This vulnerability allows a local user to run programs with higher permissions than they should have, potentially giving them control over the system. However, the user must first exploit a timing issue in the Tencent PC Manager app, which requires some technical skill.

tencentpcmanager
Exploit Available
about 1 month agoFeb 23, 2026
CVE-2025-639457.4

This vulnerability allows a local user to run programs with higher permissions than they should have, potentially giving them control over the system. However, the attacker must first exploit a timing issue in the app, which requires specific conditions to be met.

tencentioa
Exploit Available
about 1 month agoFeb 23, 2026
CVE-2025-45218.8

This vulnerability allows an attacker with at least Subscriber-level access to take over any user's account by changing their email address and triggering a password reset, effectively giving themselves full administrator privileges. The attacker only needs to know the donor ID of the target account to exploit this flaw.

Unknown
Exploit Available
about 2 months agoFeb 19, 2026
CVE-2025-150417.2

This vulnerability allows an attacker with a valid account on a WordPress site to change important settings, such as granting themselves administrative access. It occurs because the plugin fails to properly check if the user has permission to make these changes, making it easier for attackers to exploit the flaw.

Unknown
Exploit Available
about 2 months agoFeb 19, 2026
CVE-2025-138519.8

An attacker can gain full control of a WordPress site by registering as an administrator without any prior authentication, simply by manipulating a specific parameter during the user registration process. This vulnerability affects all versions of the Buyent Classified plugin up to 1.0.7, allowing anyone to exploit it without needing a valid account.

Unknown
Exploit Available
about 2 months agoFeb 19, 2026
CVE-2025-135639.8

This vulnerability allows attackers to register as an administrator on a WordPress site using the Lizza LMS Pro plugin, giving them full control over the site. It can be exploited by anyone without needing to log in, as the plugin does not properly check user roles during registration.

Unknown
Exploit Available
about 2 months agoFeb 19, 2026
CVE-2025-128829.8

This vulnerability allows attackers to gain administrator privileges on a WordPress site simply by creating a new user account and choosing their own role. It affects versions of the Clasifico Listing plugin up to 2.0 and can be exploited by anyone, even those who are not logged in.

Unknown
Theoretical
about 2 months agoFeb 19, 2026
CVE-2025-128458.8

This vulnerability allows attackers with at least Subscriber-level access to view sensitive email log information from the Tablesome plugin, which could lead to unauthorized password resets. It requires the plugin's table log feature to be enabled, making it easier for attackers to gain access to user accounts.

Unknown
Theoretical
about 2 months agoFeb 19, 2026
CVE-2026-19379.8

This vulnerability allows attackers with Shop Manager-level access or higher to change important settings on a WordPress site, potentially giving them administrative access. They can exploit this flaw to allow new users to register as administrators, which could lead to full control over the site.

Unknown
Exploit Available
about 2 months agoFeb 18, 2026
CVE-2026-236488.5

This vulnerability allows an attacker with local access to a Glory RBG-100 recycler system to gain root privileges by modifying important system files. The issue arises because some of these files can be written to and executed by regular users, making it easy for an attacker to replace them with malicious versions.

Unknown
Exploit Available
about 2 months agoFeb 17, 2026
CVE-2026-25635.3

An attacker can remotely gain higher privileges on the JingDong JD Cloud Box AX6600, potentially allowing them to take control of the device. This vulnerability affects specific firmware versions and can be exploited without needing physical access to the device.

jdcloudax6600 firmware
Exploit Available
about 2 months agoFeb 16, 2026
CVE-2026-25625.3

This vulnerability allows an attacker to gain higher-level access to the JingDong JD Cloud Box AX6600 from a remote location, potentially letting them control the device. The issue arises from a flaw in how the device handles certain input, and it affects specific firmware versions up to 4.5.1.r4533.

jdcloudax6600 firmware
Exploit Available
about 2 months agoFeb 16, 2026
CVE-2026-25615.3

An attacker can remotely gain higher privileges on the JingDong JD Cloud Box AX6600, potentially allowing them to take control of the device. This vulnerability affects specific firmware versions and can be exploited without needing physical access to the device.

jdcloudax6600 firmware
Exploit Available
about 2 months agoFeb 16, 2026
CVE-2026-263699.3

This vulnerability allows a low-privileged user to trick the system into giving them administrative access, letting them change device settings and control the entire smart home system. To exploit this, the attacker just needs to send a specially crafted request to the server, without needing any special permissions.

Unknown
Exploit Available
about 2 months agoFeb 15, 2026
CVE-2026-263688.7

An attacker can take over any user account, including those with administrative privileges, by resetting passwords without needing the current password. This vulnerability affects low-privileged users who can send a specific request to the server, allowing them to gain full control over other accounts.

Unknown
Theoretical
about 2 months agoFeb 15, 2026
CVE-2025-85729.8

This vulnerability allows attackers to create accounts with high-level permissions, including administrator access, on WordPress sites using the Truelysell Core plugin version 1.8.7 or earlier. The issue arises because the plugin does not properly check user roles during registration, meaning even someone who is not logged in can exploit this flaw.

Unknown
Exploit Available
about 2 months agoFeb 14, 2026
CVE-2025-17905.8

This vulnerability allows a low-privileged Windows user to gain higher-level access on a system running the Genetec Sipelia Plugin. The attacker must already be logged in with an account that has limited permissions to exploit this flaw.

Unknown
Exploit Available
about 2 months agoFeb 13, 2026
Showing 21 to 40 of 49 results