CVE-2025-15689
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
CVSS
9.8
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 20 ago 2026 · Última mod.: 20 ago 2026 · CWE-266
Sin historial EPSS suficiente todavía.
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-769996.3 MED—
———A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.5hCVE-2026-666829.8 CRÍ—
———Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.4hCVE-2026-118619.6 CRÍ—
——0A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.7hCVE-2026-733909.8 CRÍ—
——0Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.5hCVE-2026-733479.8 CRÍ—
——0Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.5hCVE-2026-759786.3 MED20.0%
——6A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads to permission issues. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.8h