VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1095 CVEsRSS

CVE-2026-73946Critical· 9.1
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privile…

▾ Midnightoracle · access_managerEPSS 0.49%via NVD
CVE-2026-73945Critical· 9.9
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileg…

▾ Midnightoracle · access_managerEPSS 0.43%via NVD
CVE-2026-73943High· 7.6
1w ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged at…

▾ Twilightoracle · identity_managerEPSS 0.34%via NVD
CVE-2026-73942High· 8.8
1w ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged att…

▾ Twilightoracle · identity_managerEPSS 0.43%via NVD
CVE-2026-73941High· 8.6
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthentica…

▾ Twilightoracle · access_managerEPSS 0.41%via NVD
CVE-2026-73926High· 8.7
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privile…

▾ Twilightoracle · access_managerEPSS 0.41%via NVD
CVE-2026-71163Critical· 9.9
1w ago

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine)

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileg…

▾ Midnightoracle · access_managerEPSS 0.39%via NVD
CVE-2026-71047High· 8.8
1w ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker wit…

▾ Twilightoracle · identity_managerEPSS 0.43%via NVD
CVE-2026-70915High· 8.8
1w ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker wit…

▾ Twilightoracle · identity_managerEPSS 0.43%via NVD
CVE-2026-70755Medium· 6.5
1w ago

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download)

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileg…

▾ SunlitOracle Corporation · Oracle Web Applications Desktop IntegratorEPSS 0.34%via NVD
CVE-2026-62597Medium· 6.5
1w ago

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management)

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privil…

▾ SunlitOracle Corporation · Oracle Enterprise Manager Base PlatformEPSS 0.30%via NVD
CVE-2026-76681High· 8.5
1w ago

A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level

A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privileges to access sensitive information beyond what is authorized by the user's existing privilege level. Successful e…

▾ Twilightarubanetworks · edgeconnect_sd-wan_orchestratorEPSS 0.35%via NVD
CVE-2026-90969Medium· 6.5
1w ago

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing end…

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing end…

▾ SunlitDevolutions · ServerEPSS 0.35%via NVD
CVE-2026-84048Medium· 6.3
1w ago

Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attack…

Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attack…

▾ Sunlitjoomgalleryfriends.net · JoomGallery extension for JoomlaEPSS 0.50%via NVD
CVE-2026-91849Medium· 6.3PoC
1w ago

A security flaw has been discovered in WuzhiCMS up to 4.1.0

A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in …

▾ TwilightEPSS 0.37%via NVD
CVE-2026-63695Critical· 9.8
1w ago

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

▾ MidnightDell · SmartFabric OS10 SoftwareEPSS 0.50%via NVD
CVE-2026-91005Medium· 6.3
1w ago

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture Upload. Performing a manipulation of t…

▾ SunlitSourceCodester · Online Faculty Clearance SystemEPSS 0.37%via NVD
CVE-2026-90881Medium· 5.3PoC
1w ago

A weakness has been identified in D-Link DIR-882 up to 20260814

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launc…

▾ TwilightD-Link · DIR-882EPSS 0.83%via NVD
CVE-2026-90857Medium· 6.3PoC
1w ago

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Upload. Performing a manipulation of the argument…

▾ TwilightSourceCodester · College Notes Gallery Management SystemEPSS 0.37%via NVD
CVE-2026-90851Medium· 6.3PoC
1w ago

A flaw has been found in PHPGurukul Hostel Management System 3.0

A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the a…

▾ TwilightPHPGurukul · Hostel Management SystemEPSS 0.37%via NVD
CVE-2026-84491Medium· 5.5
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.

▾ Sunlitapple · ipadosEPSS 0.14%via NVD
CVE-2026-65345Medium· 5.5
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitiv…

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2026-43762Medium· 5.5
1w ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. An app may be able to access user-sensitive data.

▾ Sunlitapple · ipadosEPSS 0.16%via NVD
CVE-2026-84585Medium· 5.5
1w ago

A permissions issue was addressed with improved state management

A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access local network devices without user consent.

▾ Sunlitapple · macosEPSS 0.16%via NVD
CVE-2026-65380Medium· 5.5
1w ago

An issue existed in the handling of snapshots

An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Golden Gate 27. An app may be able to access protected user data.

▾ Sunlitapple · macosEPSS 0.17%via NVD
CVE-2026-64712High· 7.8
1w ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

▾ Twilightapple · macosEPSS 0.15%via NVD
CVE-2026-65362High· 7.8
1w ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

▾ Twilightapple · macosEPSS 0.15%via NVD
CVE-2026-65361Medium· 5.5
1w ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.15%via NVD
CVE-2026-84573Medium· 5.5
1w ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.15%via NVD
CVE-2026-65383Medium· 4.4
1w ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may bypass Gatekeeper checks.

▾ Sunlitapple · macosEPSS 0.13%via NVD
CWE-284 vulnerabilities (CVEs) — page 15 · VulnSea