VulnSea

CWE-269

CVEs classified under CWE-269, newest first.

470 CVEsRSS

CVE-2026-60678High· 8.8
2mo ago

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker wit…

▾ Twilightoracle · e-business_suiteEPSS 0.43%via NVD
CVE-2026-61311High· 8.8
2mo ago

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-61188High· 7.5
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). The supported version that is affected is 6.2.4. Difficult to exploit vulnerability allows low privile…

▾ Twilightoracle · agile_product_lifecycle_management_for_processEPSS 0.33%via NVD
CVE-2026-61182Medium· 6.7
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows high privilege…

▾ Sunlitoracle · agile_product_lifecycle_management_for_processEPSS 0.18%via NVD
CVE-2026-61180High· 8.8
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows…

▾ Twilightoracle · agile_product_lifecycle_management_for_processEPSS 0.43%via NVD
CVE-2026-61179High· 8.8
2mo ago

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management)

Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows…

▾ Twilightoracle · agile_product_lifecycle_management_for_processEPSS 0.43%via NVD
CVE-2026-61114High· 7.5
2mo ago

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges)

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged atta…

▾ Twilightoracle · application_object_libraryEPSS 0.33%via NVD
CVE-2026-61110High· 8.8
2mo ago

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch)

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network …

▾ Twilightoracle · applications_dbaEPSS 0.43%via NVD
CVE-2026-61107High· 7.2
2mo ago

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker …

▾ Twilightoracle · applications_dbaEPSS 0.49%via NVD
CVE-2026-60661High· 7.8
2mo ago

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems)

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure …

▾ Twilightoracle · solarisEPSS 0.13%via NVD
CVE-2026-60567Critical· 9.1
2mo ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated at…

▾ Midnightoracle · identity_managerEPSS 0.43%via NVD
CVE-2026-60566Critical· 9.8
2mo ago

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools)

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated at…

▾ Midnightoracle · webcenter_portalEPSS 0.51%via NVD
CVE-2026-60530High· 7.8
2mo ago

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so)

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to …

▾ Twilightoracle · http_serverEPSS 0.16%via NVD
CVE-2026-60454High· 7.8
2mo ago

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with log…

▾ Twilightoracle · http_serverEPSS 0.16%via NVD
CVE-2026-60406Medium· 6.7
2mo ago

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator)

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privile…

▾ Sunlitoracle · timesten_in-memory_databaseEPSS 0.18%via NVD
CVE-2026-60546High· 7.2
2mo ago

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight)

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privi…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-44231Critical· 9.1
2mo ago

RT is an open source, enterprise-grade issue and ticket tracking system

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged…

▾ Midnightbestpractical · request_trackerEPSS 0.41%via NVD
CVE-2026-53515High· 7.1
2mo ago

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

@better-auth/sso: SSO provider may allow registration for any org member without a checking their role

▾ Twilightbetter-auth · @better-auth/ssoEPSS 0.43%via GHSA
CVE-2026-47870High· 7.1
2mo ago

VMware Avi Load Balancer contains a privilege escalation vulnerability

VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 3…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-47868High· 7.8
2mo ago

VMware Avi Load Balancer contains a local privilege escalation vulnerability

VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31…

▾ TwilightEPSS 0.14%via NVD
CVE-2026-48010Medium· 6.5
2mo ago

Shopware is an open commerce platform

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non…

▾ SunlitEPSS 0.47%via NVD
GHSA-48qw-824m-86prHigh· 7.7
2mo ago

ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read

ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read

▾ Twilightarcadedb · com.arcadedb:arcadedb-servervia GHSA
CVE-2026-49176High· 7.8PoC
2mo ago

Windows WalletService Elevation of Privilege Vulnerability

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50295Medium· 5.5
2mo ago

Windows Zero Trust DNS Security Feature Bypass Vulnerability

Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.

▾ SunlitMicrosoft · Windows 11 Version 24H2EPSS 0.30%via CVEORG
CVE-2026-50343High· 7.8PoC
2mo ago

Microsoft Install Service Elevation of Privilege Vulnerability

Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1809EPSS 0.30%via CVEORG
CVE-2026-50391High· 7.8
2mo ago

Windows Group Policy Elevation of Privilege Vulnerability

Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-61463High· 8.8PoC
2mo ago

Shiori Authenticated Privilege Escalation via PATCH /api/v1/auth/account

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted P…

▾ Midnightgo-shiori · shioriEPSS 0.52%via CVEORG
CVE-2026-59245High· 8.1
2mo ago

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently gran…

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently gran…

▾ Twilightapache · apache-airflow-providers-fabEPSS 0.60%via NVD
CVE-2026-59260High· 8.8
2mo ago

OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments

OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global o…

▾ TwilightEPSS 0.68%via NVD
CVE-2026-14262High· 8.8
2mo ago

The Simple JWT Login – Allows you to use JWT on REST endpoints

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerabilit…

▾ TwilightEPSS 0.74%via NVD
CWE-269 vulnerabilities (CVEs) — page 13 · VulnSea