CVE-2026-59541
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
CVSS
8.8
Alto
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 23 jul 2026 · Última mod.: 23 jul 2026 · CWE-266
Sin historial EPSS suficiente todavía.
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-619519.8 CRÍ—
——0Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.6hCVE-2026-595409.8 CRÍ—
——0Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.6hCVE-2026-472378.0 ALT24.1%
——7Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kubeflow UI or APIs, such as the Dashboard, Pipelines API, or Notebooks. With this token, the attacker can take over the user's account and the data that is processed by that user. The attacker needs a valid user with the ``kubeflow-edit`` role / Contributor role in a random Kubeflow namespace to perform this attack. This is given if _Automatic Profile Creation_ is enabled. Version 26.03-rc.1 fixes the issue.1dCVE-2026-218248.8 ALT14.7%
——4HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.2dCVE-2026-162244.3 MED12.8%
——4A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The identifier of the patch is dc2b6910a423b3bfadeffaa303e1ba75cfb33900. Applying a patch is the recommended action to fix this issue.3dCVE-2026-161996.3 MED11.2%
——3A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used.3d