VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1000 CVEsRSS

CVE-2026-90922Medium· 5.3
4d ago

The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a pai…

The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a pai…

SunlitEPSS 0.18%via NVD
CVE-2026-91019Medium· 4.9
4d ago

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe…

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe…

SunlitEPSS 0.22%via NVD
CVE-2026-20192Critical· 10.0
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal securi…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal securi…

MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 0.43%via NVD
CVE-2026-20332Critical· 9.9
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software en…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software en…

MidnightCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.30%via NVD
CVE-2026-20322Critical· 9.9
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release…

MidnightCisco · Cisco Nexus DashboardEPSS 0.27%via NVD
CVE-2026-20121Medium· 5.3
5d ago

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthen…

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthen…

SunlitCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.49%via NVD
CVE-2026-20120Medium· 5.8
5d ago

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthen…

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthen…

SunlitCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.41%via NVD
CVE-2026-88817High· 8.7
5d ago

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, …

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, …

TwilightCuriosity GmbH · Curiosity WorkspaceEPSS 0.27%via NVD
CVE-2026-92357Medium· 4.3
5d ago

A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0

A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the argument current[segment] leads to information disc…

Sunlita2ui-project · a2uiEPSS 0.30%via NVD
CVE-2026-89328Low· 3.8
5d ago

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board…

SunlitEPSS 0.21%via NVD
CVE-2026-87959Medium· 5.4
5d ago

The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, including the API key us…

The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level access to overwrite those settings, including the API key us…

SunlitEPSS 0.18%via NVD
CVE-2026-82126Low· 2.7
5d ago

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific post they request schema generation for, allowing users with the contributor role and above to obtain the c…

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific post they request schema generation for, allowing users with the contributor role and above to obtain the c…

SunlitEPSS 0.29%via NVD
CVE-2026-92247Medium· 4.7PoC
5d ago

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload.…

Twilightsynaptikcms · synaptik-cmsEPSS 0.29%via NVD
CVE-2026-83368High· 7.0
6d ago

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle Graa…

TwilightOracle Corporation · Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVMEPSS 0.21%via NVD
CVE-2026-87288High· 8.1
6d ago

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network ac…

TwilightOracle Corporation · Oracle GraalVMEPSS 0.22%via NVD
CVE-2026-87287High· 8.1
6d ago

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network ac…

TwilightOracle Corporation · Oracle GraalVMEPSS 0.22%via NVD
CVE-2026-87286High· 8.1
6d ago

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network ac…

TwilightOracle Corporation · Oracle GraalVMEPSS 0.22%via NVD
CVE-2026-87285Medium· 6.0
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.14%via NVD
CVE-2026-87284Low· 3.2
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.14%via NVD
CVE-2026-87283Medium· 6.0
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.11%via NVD
CVE-2026-87282Medium· 6.0
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.14%via NVD
CVE-2026-87281Low· 3.2
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.15%via NVD
CVE-2026-87280Medium· 4.2
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.13%via NVD
CVE-2026-87279Medium· 6.1
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastru…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.13%via NVD
CVE-2026-87278Medium· 6.1
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastr…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.14%via NVD
CVE-2026-87276High· 7.5
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrast…

TwilightOracle Corporation · Oracle VM VirtualBoxEPSS 0.11%via NVD
CVE-2026-87275Medium· 4.6
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.11%via NVD
CVE-2026-87267Medium· 5.3
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with network access via R…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.23%via NVD
CVE-2026-87266High· 8.2
6d ago

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server)

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access…

TwilightOracle Corporation · Oracle Agile PLMEPSS 0.34%via NVD
CVE-2026-87265High· 8.1
6d ago

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue)

Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network ac…

TwilightOracle Corporation · Oracle PurchasingEPSS 0.28%via NVD
CWE-284 vulnerabilities (CVEs) — page 2 · VulnSea