VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

814 CVEsRSS

CVE-2026-86447Medium· 5.3
1w ago

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every enrolled student's display name and user identifier against …

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every enrolled student's display name and user identifier against …

▾ SunlitEPSS 0.34%via NVD
CVE-2026-86445Medium· 5.3
1w ago

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz que…

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the text, identifier and type of every published quiz que…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-85572Medium· 4.3
1w ago

The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson discussion content, allowing any authenticated user, such as a subscriber, to read comments from courses they are …

The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson discussion content, allowing any authenticated user, such as a subscriber, to read comments from courses they are …

▾ SunlitEPSS 0.29%via NVD
CVE-2026-85349Medium· 4.3
1w ago

The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the pr…

The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the pr…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-82124Medium· 5.3
1w ago

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the con…

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it generates, allowing unauthenticated users to obtain the con…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-78474Medium· 5.3
1w ago

The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and cust…

The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and cust…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-88065High· 7.5
1w ago

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules

`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/ph…

▾ TwilightNIAEFEUP · tts-beEPSS 0.51%via NVD
CVE-2026-87225High· 7.1
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with n…

▾ Twilightoracle · hyperion_financial_managementEPSS 0.42%via NVD
CVE-2026-87221High· 7.5
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Twilightoracle · hyperion_financial_managementEPSS 0.44%via NVD
CVE-2026-87209High· 7.1
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with n…

▾ Twilightoracle · hyperion_financial_managementEPSS 0.42%via NVD
CVE-2026-87127High· 7.7
1w ago

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing)

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network a…

▾ Twilightoracle · purchasingEPSS 0.39%via NVD
CVE-2026-83443Medium· 6.5
1w ago

Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with networ…

▾ SunlitOracle Corporation · Oracle AssetsEPSS 0.37%via NVD
CVE-2026-83437High· 7.7
1w ago

Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management)

Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with net…

▾ TwilightOracle Corporation · Oracle EngineeringEPSS 0.37%via NVD
CVE-2026-83425High· 8.5
1w ago

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows …

▾ TwilightOracle Corporation · Oracle Complex Maintenance, Repair and OverhaulEPSS 0.40%via NVD
CVE-2026-83424High· 7.5
1w ago

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper)

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated atta…

▾ TwilightOracle Corporation · Oracle JDeveloperEPSS 0.42%via NVD
CVE-2026-83419Medium· 5.4
1w ago

Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP)

Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerab…

▾ SunlitOracle Corporation · Oracle Communications Cloud Native Core Security Edge Protection ProxyEPSS 0.25%via NVD
CVE-2026-83417High· 7.1
1w ago

Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP)

Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP). Supported versions that are affected are 26.1.200 and 25.2.201. Easily exploitable vulnerab…

▾ TwilightOracle Corporation · Oracle Communications Cloud Native Core Security Edge Protection ProxyEPSS 0.25%via NVD
CVE-2026-83414Low· 2.5
1w ago

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infr…

▾ Sunlitoracle · coherenceEPSS 0.13%via NVD
CVE-2026-83354Medium· 6.3
1w ago

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access vi…

▾ SunlitOracle Corporation · Oracle CoherenceEPSS 0.30%via NVD
CVE-2026-83352High· 7.1
1w ago

Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install)

Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network acces…

▾ TwilightOracle Corporation · Oracle XML GatewayEPSS 0.40%via NVD
CVE-2026-83326High· 7.5
1w ago

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration)

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network a…

▾ TwilightOracle Corporation · Siebel CRM IntegrationEPSS 0.42%via NVD
CVE-2026-83302High· 8.5
1w ago

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security)

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network…

▾ TwilightOracle Corporation · Oracle BI PublisherEPSS 0.40%via NVD
CVE-2026-83300High· 7.1
1w ago

Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install)

Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network acces…

▾ TwilightOracle Corporation · Oracle XML GatewayEPSS 0.40%via NVD
CVE-2026-83287High· 7.7
1w ago

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services)

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vul…

▾ TwilightOracle Corporation · Oracle Business Intelligence Enterprise EditionEPSS 0.37%via NVD
CVE-2026-83279Medium· 5.5
1w ago

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client)

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to t…

▾ SunlitOracle Corporation · Oracle Agile PLM MCAD ConnectorEPSS 0.15%via NVD
CVE-2026-83277High· 7.3
1w ago

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client)

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to t…

▾ TwilightOracle Corporation · Oracle Agile PLM MCAD ConnectorEPSS 0.15%via NVD
CVE-2026-83274Medium· 5.5
1w ago

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client)

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to t…

▾ SunlitOracle Corporation · Oracle Agile PLM MCAD ConnectorEPSS 0.15%via NVD
CVE-2026-83259High· 7.1
1w ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privil…

▾ TwilightOracle Corporation · Oracle Commerce Guided Search / Oracle Commerce Experience ManagerEPSS 0.40%via NVD
CVE-2026-83238High· 7.1
1w ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privil…

▾ TwilightOracle Corporation · Oracle Commerce Guided Search / Oracle Commerce Experience ManagerEPSS 0.40%via NVD
CVE-2026-83237High· 7.1
1w ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privil…

▾ TwilightOracle Corporation · Oracle Commerce Guided Search / Oracle Commerce Experience ManagerEPSS 0.40%via NVD
CWE-200 vulnerabilities (CVEs) — page 6 · VulnSea