VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1095 CVEsRSS

CVE-2026-65403Medium· 5.5
1w ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. An app may be able to access sensi…

▾ Sunlitapple · ipadosEPSS 0.14%via NVD
CVE-2026-84535High· 8.2
1w ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.

▾ Twilightapple · macosEPSS 0.16%via NVD
CVE-2026-84574Medium· 4.4
1w ago

A permissions issue was addressed with improved state management

A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to bypass Privacy preferences.

▾ Sunlitapple · macosEPSS 0.14%via NVD
CVE-2026-86905Medium· 5.5
1w ago

This issue was addressed by removing the vulnerable code

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to delete credentials stored in Keychain.

▾ Sunlitapple · ipadosEPSS 0.14%via NVD
CVE-2026-84555Medium· 5.5
1w ago

An authorization issue was addressed with improved access control

An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.15%via NVD
CVE-2026-43741Medium· 5.5
1w ago

A logic issue was addressed with improved state management

A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.

▾ Sunlitapple · macosEPSS 0.16%via NVD
CVE-2026-28937Medium· 5.5
1w ago

This issue was addressed through improved state management

This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.16%via NVD
CVE-2026-19290High· 7.5
1w ago

IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control.

IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control.

▾ TwilightIBM · Sterling File GatewayEPSS 0.40%via NVD
CVE-2026-90811Low· 3.3PoC
1w ago

A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0

A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0. This affects the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Permission Manif…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.15%via NVD
CVE-2026-76441Critical· 9.8
1w ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review r…

▾ MidnightCisco · Cisco Secure Email and Web ManagerEPSS 0.53%via NVD
CVE-2026-46696Low· 3.3
1w ago

October System provides the system module for October Content Management System

October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. …

▾ Sunlitoctobercms · systemEPSS 0.27%via NVD
CVE-2026-90898Critical· 9.8PoC
1w ago

Bifrost registers MCP clients through its management API

Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_conf…

▾ Abyssalmaximhq · github.com/maximhq/bifrost/transportsEPSS 0.62%via NVD
CVE-2026-81566Medium· 5.1
1w ago

Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly

Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not per…

▾ Sunlitjoomshaper.com · SP Page Builder (Free and Pro) extension for JoomlaEPSS 0.39%via NVD
CVE-2026-12258Critical· 9.2
1w ago

Inadequate access control in Hiperdino’s REST v1.0 API

Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, …

▾ MidnightHiperdino · REST APIEPSS 0.40%via NVD
CVE-2026-54628High· 8.6PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without …

▾ Midnightjulien040 · anyqueryEPSS 0.60%via NVD
CVE-2026-54629High· 7.5
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, a…

▾ Twilightjulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-50006Critical· 9.1PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacke…

▾ Abyssaljulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-90493High· 8.8PoC
2w ago

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows

A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper acces…

▾ MidnightTonec · Internet Download ManagerEPSS 0.15%via NVD
CVE-2026-90503Low· 2.3
2w ago

A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714

A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information d…

▾ SunlitChengdu Qilu Technology · LudashiEPSS 0.16%via NVD
CVE-2026-90500Medium· 6.3PoC
2w ago

A weakness has been identified in lenve vhr 1.0-SNAPSHOT

A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upl…

▾ Twilightlenve · vhrEPSS 0.35%via NVD
CVE-2026-90507Medium· 6.3PoC
2w ago

A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such ma…

▾ Twilightvvbbnn00 · WARP-Clash-APIEPSS 0.38%via NVD
CVE-2026-90519Medium· 6.3PoC
2w ago

A weakness has been identified in PHPGurukul Bank Locker Management System 1.0

A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remo…

▾ TwilightPHPGurukul · Bank Locker Management SystemEPSS 0.37%via NVD
CVE-2026-90565Medium· 5.3PoC
2w ago

A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid resul…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.53%via NVD
CVE-2026-90603High· 7.3
2w ago

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-prox…

▾ TwilightAnil-matcha · Open-Generative-AIEPSS 0.50%via NVD
CVE-2026-90518Medium· 6.3PoC
2w ago

A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0

A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may …

▾ TwilightPHPGurukul · Bank Locker Management SystemEPSS 0.37%via NVD
CVE-2026-87918Medium· 5.3
2w ago

The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls,…

The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls,…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-87892Medium· 5.3
2w ago

The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed…

The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-87891Medium· 6.5
2w ago

The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as un…

The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as un…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-77753Medium· 5.5
2w ago

The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient …

The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient …

▾ SunlitEPSS 0.32%via NVD
CVE-2026-77689Medium· 5.3
2w ago

The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking…

The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking…

▾ SunlitEPSS 0.30%via NVD
CWE-284 vulnerabilities (CVEs) — page 16 · VulnSea