VulnSea

CWE-1220

CVEs classified under CWE-1220, newest first.

35 CVEsRSS

CVE-2026-92958High· 8.5PoC
5d ago

vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM

vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.g. require: { builtin: ['*', '-fs', '-child_process'] }), negative entries are matched …

Midnightpatriksimek · vm2EPSS 0.28%via NVD
CVE-2026-86338Medium· 6.0
6d ago

Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used a…

Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is replaced with an expression that evaluates to nil, so a filter cannot be used a…

Sunlitash-project · ashEPSS 0.32%via NVD
CVE-2026-92057Critical· 9.1⚖ disputed
1w ago

Mitigation bypass in the Enterprise Policies component

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.15%via NVD
CVE-2026-55073Medium· 6.2PoC
1w ago

WeasyPrint helps web developers to create PDF documents

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through t…

TwilightKozea · WeasyPrintEPSS 0.19%via NVD
CVE-2026-77480High· 8.8
2w ago

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.53%via NVD
CVE-2026-69267Medium· 6.5
2w ago

Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.

Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1809EPSS 0.26%via NVD
CVE-2026-66814High· 8.8
2w ago

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.42%via NVD
CVE-2026-78230Medium· 6.0
2w ago

AshAi exposes Ash read actions to language-model tool calls

AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies …

Sunlitash-project · ash_aiEPSS 0.25%via NVD
CVE-2026-78216Medium· 6.0
2w ago

AshLua exposes Ash read actions to Lua scripts run through an eval action

AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash fi…

Sunlitash-project · ash_luaEPSS 0.25%via NVD
CVE-2026-85594Critical· 9.8⚖ disputed
2w ago

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from th…

Midnighttraefik · traefikEPSS 0.26%via NVD
CVE-2026-15431None
2w ago

A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0

A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient acc…

SunlitEPSS 0.09%via NVD
CVE-2026-74994Medium· 6.0
3w ago

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user ad…

SunlitErlang · otpEPSS 0.36%via NVD
CVE-2026-82474High· 7.8
3w ago

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.13%via NVD
CVE-2026-68868Medium· 6.5
1mo ago

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal c…

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal c…

Sunlitapache · apache-airflow-providers-googleEPSS 0.48%via NVD
CVE-2026-62721High· 7.8
1mo ago

Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.41%via NVD
CVE-2026-71327High· 8.1
1mo ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go bui…

Twilighttraefik · traefikEPSS 0.35%via NVD
CVE-2026-16108Medium· 4.3
2mo ago

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated admini…

Sunlitredhat · build_of_keycloakEPSS 0.21%via NVD
CVE-2026-16106Medium· 4.9
2mo ago

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks…

Sunlitredhat · build_of_keycloakEPSS 0.42%via NVD
CVE-2026-55006High· 7.8
2mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.30%via CVEORG
CVE-2026-56155High· 7.8CISA KEV0dayPoC
2mo ago

Active Directory Federation Services Elevation of Privilege Vulnerability

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

AbyssalMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2026-48581High· 7.8
2mo ago

Surface Broker SDMA Elevation of Privilege Vulnerability

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Microsoft Surface GoEPSS 0.30%via CVEORG
CVE-2026-50405High· 7.8
2mo ago

Windows Filtering Platform Elevation of Privilege Vulnerability

Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-50502High· 8.0
2mo ago

Windows Event Logging Service Remote Code Execution Vulnerability

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.65%via CVEORG
CVE-2026-49170High· 7.8
2mo ago

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-14615Medium· 4.3
2mo ago

A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services

A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly filter child groups based on the caller's specific permissio…

SunlitEPSS 0.32%via NVD
CVE-2026-54517Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Information disclosure via improper JsonView filter application (CVE-2026-54517)

A flaw was found in jackson-databind. A remote attacker can exploit this vulnerability due to an issue in how active-view (@JsonView) filters are applied. Specifically, setterless collections annotated with a restricted @JsonView can be po…

SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2025-54518High· 7.0
4mo ago

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

TwilightAMD · AMD EPYC™ 7002 Series ProcessorsEPSS 0.29%via NVD
CVE-2026-41326High· 8.2
5mo ago

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile han…

Twilightkatacontainers · confidential_containersEPSS 0.35%via NVD
CVE-2026-39363High· 7.5PoC
5mo ago

Vite is a frontend tooling framework for JavaScript

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custo…

Midnightvitejs · viteEPSS 3.4%via NVD
CVE-2025-20628None
5mo ago

An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode.…

An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector Servers (RCS) running in client mode.…

SunlitEPSS 0.24%via NVD
CWE-1220 vulnerabilities (CVEs) · VulnSea