VulnSea

CWE-280

CVEs classified under CWE-280, newest first.

25 CVEsRSS

CVE-2026-54471Low· 3.5
5d ago

Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability

Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading …

SunlitDell · SmartFabric ManagerEPSS 0.17%via NVD
CVE-2026-1759Medium· 6.5
1w ago

Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

SunlitSecomea · GateManagerEPSS 0.26%via NVD
CVE-2026-43786High· 7.8
1w ago

This issue was addressed with additional entitlement checks

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

Twilightapple · macosEPSS 0.15%via NVD
CVE-2026-86917High· 7.8
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

Twilightapple · macosEPSS 0.11%via NVD
CVE-2026-64701High· 7.8
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

Twilightapple · macosEPSS 0.14%via NVD
CVE-2026-84631High· 7.8
1w ago

This issue was addressed with additional entitlement checks

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to gain root privileges.

Twilightapple · macosEPSS 0.11%via NVD
CVE-2026-21099Medium· 5.5
1w ago

Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

Sunlitsamsung · androidEPSS 0.09%via NVD
CVE-2026-69907High· 7.8
2w ago

Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.

Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.28%via NVD
CVE-2026-32639Medium· 6.8
3w ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend us…

Sunlitwinter · winter/wn-cms-moduleEPSS 0.28%via NVD
CVE-2026-54259Medium· 4.3
1mo ago

Wagtail: Improper restriction handling on Documents and Images chosen endpoints

Wagtail: Improper restriction handling on Documents and Images chosen endpoints

Sunlitwagtail · wagtailEPSS 0.27%via GHSA
CVE-2026-54261Medium· 6.5
1mo ago

Wagtail: Improper permission handling in image preview

Wagtail: Improper permission handling in image preview

Sunlitwagtail · wagtailEPSS 0.34%via GHSA
CVE-2026-54262Medium· 4.3
1mo ago

Wagtail: Pages translations can be created without page permissions when using simple_translation

Wagtail: Pages translations can be created without page permissions when using simple_translation

Sunlitwagtail · wagtailEPSS 0.27%via GHSA
CVE-2026-55468Medium· 4.3
1mo ago

Wagtail: Improper restriction handling on Pages admin API

Wagtail: Improper restriction handling on Pages admin API

Sunlitwagtail · wagtailEPSS 0.20%via OSV
GHSA-92hv-j533-69wcLow· 3.7
1mo ago

Wagtail: Identification of documents by SHA1 hash

Wagtail: Identification of documents by SHA1 hash

Sunlitwagtail · wagtailvia GHSA
GHSA-c2xx-cjmh-9q8fMedium· 5.3
1mo ago

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

Sunlitwagtail · wagtailvia GHSA
GHSA-x5cx-w6p2-mxf2Medium· 6.5
1mo ago

Wagtail: Improper permission handling when copying snippets

Wagtail: Improper permission handling when copying snippets

Sunlitwagtail · wagtailvia GHSA
GHSA-jm5p-837g-rv8gMedium· 6.5
1mo ago

Wagtail: Improper restriction handling on Page translation API endpoint

Wagtail: Improper restriction handling on Page translation API endpoint

Sunlitwagtail · wagtailvia GHSA
CVE-2026-18860High· 8.7
1mo ago

Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org

Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To m…

TwilightEPSS 0.30%via NVD
CVE-2026-58416Medium· 6.3
2mo ago

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

Sunlitgitea.dev · gitea.devEPSS 0.25%via GHSA
CVE-2026-45196None
2mo ago

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation.

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation.

SunlitEPSS 0.14%via NVD
CVE-2026-46054High· 7.1
3mo ago

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access t…

In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access t…

Twilightlinux · linux_kernelEPSS 0.12%via NVD
CVE-2026-2340Medium· 6.5
3mo ago

A flaw was found in Samba’s vfs_worm module

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename o…

Sunlitredhat · openshift_container_platformEPSS 0.94%via NVD
CVE-2026-21733High· 7.3
5mo ago

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files. This is caused by improper handling of GPU memory reservation protecti…

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files. This is caused by improper handling of GPU memory reservation protecti…

TwilightEPSS 0.10%via NVD
CVE-2026-2123High· 7.8
5mo ago

A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows

A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Phili…

Twilightmicrofocus · operations_agentEPSS 0.10%via NVD
CVE-2026-20817High· 7.8PoC
8mo ago

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Midnightmicrosoft · windows_10_21h2EPSS 5.5%via NVD
CWE-280 vulnerabilities (CVEs) · VulnSea