VulnSea

CWE-1390

CVEs classified under CWE-1390, newest first.

10 CVEsRSS

CVE-2026-77483High· 8.8
1w ago

Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.

Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sql_server_2017EPSS 0.53%via NVD
CVE-2026-73025Critical· 9.8
1w ago

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

Midnightmicrosoft · windows_10_1607EPSS 0.90%via NVD
CVE-2026-62895High· 8.8
1w ago

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

TwilightMicrosoft · Azure Arc SQL Server ExtensionEPSS 0.72%via NVD
CVE-2026-80219High· 8.7
1w ago

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

TwilightRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.23%via NVD
CVE-2026-44476Medium· 6.3PoC
3w ago

Doorkeeper is an OAuth 2 provider for Ruby on Rails

Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain …

Twilightdoorkeeper-gem · doorkeeper-openid_connectEPSS 0.32%via NVD
CVE-2026-59135Medium· 5.5
1mo ago

Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_10_1607EPSS 0.32%via NVD
CVE-2026-55040Critical· 9.1CISA KEVPoC
2mo ago

Microsoft SharePoint Server Security Feature Bypass Vulnerability

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

HadalMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 51%via CVEORG
CVE-2026-0274Critical· 9.1
3mo ago

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

Midnightpaloaltonetworks · cortex_xsiam_commvaultsecurityiq_marketplaceEPSS 0.29%via NVD
CVE-2026-1693High· 7.5
6mo ago

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being depre…

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being depre…

Twilightarcinfo · pcvueEPSS 0.31%via NVD
CVE-2024-35248High· 7.3
2y ago

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Twilightmicrosoft · dynamics_365_business_centralEPSS 0.95%via NVD
CWE-1390 vulnerabilities (CVEs) · VulnSea