CVE-2026-73390
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
CVSS
9.8
Critical
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 19, 2026 · Last modified: Aug 20, 2026 · CWE-266
Not enough EPSS history yet.
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-769996.3 MED—
———A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.5hCVE-2026-666829.8 CRI—
———Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.4hCVE-2025-156899.8 CRI—
———Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.5hCVE-2026-118619.6 CRI—
——0A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.7hCVE-2026-733479.8 CRI—
——0Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.5hCVE-2026-759786.3 MED20.0%
——6A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads to permission issues. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.8h