VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1096 CVEsRSS

CVE-2026-76609None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.

Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-76608None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.

Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-76607None
1mo ago

Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???.

Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-76603None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.3 - The inineedit form controller does not perform any access checks, disclosing items to unauthorized users.

Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.3 - The inineedit form controller does not perform any access checks, disclosing items to unauthorized users.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-76601None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.

Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-76600None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks.

Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-76599None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns.

Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows listings of arbitrary database tables including columns.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-76598None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings.

Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary directory listings.

▾ SunlitEPSS 0.46%via NVD
CVE-2026-76597None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.

Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin controller allows to upload non-executable files to the webroot.

▾ SunlitEPSS 0.44%via NVD
CVE-2026-76596None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table

Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET empties the target list's table

▾ SunlitEPSS 0.41%via NVD
CVE-2026-65915Medium· 6.5
1mo ago

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to…

▾ Sunlitnltk · nltkEPSS 0.41%via NVD
CVE-2026-66916NonePoC
1mo ago

Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view

Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protec…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-55621High· 7.7
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of …

▾ Twilightlxc · github.com/lxc/incus/v7EPSS 0.34%via NVD
CVE-2026-55622High· 7.7
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an in…

▾ Twilightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.34%via NVD
CVE-2026-66309Critical· 9.1
1mo ago

Azure SQL Database Elevation of Privilege Vulnerability

Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure SQL DatabaseEPSS 0.86%via CVEORG
CVE-2026-50719Medium· 6.8
1mo ago

The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification

The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table pa…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-71038High· 7.5
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allo…

▾ Twilightoracle · commerce_guided_searchEPSS 0.41%via NVD
CVE-2026-71037Critical· 9.3
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allo…

▾ Midnightoracle · commerce_guided_searchEPSS 0.38%via NVD
CVE-2026-60759High· 7.4
1mo ago

Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthent…

▾ Twilightoracle · e-business_suiteEPSS 0.34%via NVD
CVE-2026-70852High· 8.2
1mo ago

Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations)

Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Twilightoracle · demand_planningEPSS 0.35%via NVD
CVE-2026-70846Critical· 9.6
1mo ago

Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations)

Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows low privileged attacker with n…

▾ Midnightoracle · demand_planningEPSS 0.36%via NVD
CVE-2026-70737High· 8.8
1mo ago

Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management)

Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerabi…

▾ Twilightoracle · enterprise_manager_for_systems_infrastructureEPSS 0.43%via NVD
CVE-2026-71092High· 7.5
1mo ago

Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration)

Vulnerability in the PeopleSoft Enterprise FIN Lease Administration product of Oracle PeopleSoft (component: Lease Administration). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows low privileged…

▾ Twilightoracle · peoplesoft_lease_administrationEPSS 0.13%via NVD
CVE-2026-71048High· 7.6
1mo ago

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues)

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker w…

▾ Twilightoracle · product_lifecycle_analyticsEPSS 0.32%via NVD
CVE-2026-67442Low· 2.0
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.3, DELETE /api/roles removes role definitions through server/runtime/users/usrstorage.js but does not remove the deleted role identifier from each use…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-54730None
1mo ago

authentik is an open-source identity provider

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise…

▾ SunlitEPSS 0.68%via NVD
CVE-2026-71035High· 8.1
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthen…

▾ Twilightoracle · commerce_experience_managerEPSS 0.39%via NVD
CVE-2026-71034High· 7.5
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenti…

▾ Twilightoracle · commerce_experience_managerEPSS 0.41%via NVD
CVE-2026-71033Medium· 5.5
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnera…

▾ Sunlitoracle · commerce_experience_managerEPSS 0.15%via NVD
CVE-2026-71032High· 7.2
1mo ago

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller)

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnera…

▾ Twilightoracle · commerce_experience_managerEPSS 0.27%via NVD
CWE-284 vulnerabilities (CVEs) — page 20 · VulnSea