VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1097 CVEsRSS

CVE-2026-60916Critical· 9.9
1mo ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauth…

▾ Midnightoracle · webcenter_enterprise_captureEPSS 0.37%via NVD
CVE-2026-60915High· 7.4
1mo ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network acces…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-60914High· 7.5
1mo ago

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core)

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attack…

▾ Twilightoracle · unified_directoryEPSS 0.41%via NVD
CVE-2026-60895Medium· 6.8
1mo ago

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core)

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attac…

▾ Sunlitoracle · unified_directoryEPSS 0.29%via NVD
CVE-2026-60889High· 7.5
1mo ago

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core)

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attack…

▾ Twilightoracle · unified_directoryEPSS 0.41%via NVD
CVE-2026-60866Medium· 6.5
1mo ago

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler)

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker w…

▾ Sunlitoracle · service_delivery_platformEPSS 0.27%via NVD
CVE-2026-60865Medium· 6.8
1mo ago

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler)

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privile…

▾ Sunlitoracle · service_delivery_platformEPSS 0.40%via NVD
CVE-2026-60861Critical· 9.6
1mo ago

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler)

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileg…

▾ Midnightoracle · service_delivery_platformEPSS 0.36%via NVD
CVE-2026-60860High· 8.7
1mo ago

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler)

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 14.1.2.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenti…

▾ Twilightoracle · service_delivery_platformEPSS 0.36%via NVD
CVE-2026-60850High· 7.5
1mo ago

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core)

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attack…

▾ Twilightoracle · unified_directoryEPSS 0.41%via NVD
CVE-2026-60841High· 8.5
1mo ago

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core)

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attac…

▾ Twilightoracle · unified_directoryEPSS 0.33%via NVD
CVE-2026-60830Medium· 6.5
1mo ago

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist)

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access …

▾ SunlitEPSS 0.35%via NVD
CVE-2026-60822High· 7.8
1mo ago

Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Agent)

Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Agent). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low priv…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-60808High· 7.5
1mo ago

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing)

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows low privileged attacker with logon to …

▾ TwilightEPSS 0.13%via NVD
CVE-2026-60803High· 7.4
1mo ago

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing)

Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-60753High· 7.8
1mo ago

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation)

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows low privileged attacker with logon to the inf…

▾ Twilightoracle · siebel_crm_deploymentEPSS 0.16%via NVD
CVE-2026-60707High· 8.7
1mo ago

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security)

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacke…

▾ Twilightoracle · identity_managerEPSS 0.41%via NVD
CVE-2026-60680High· 8.1
1mo ago

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low …

▾ Twilightoracle · weblogic_serverEPSS 0.38%via NVD
CVE-2026-74960High· 8.1⚖ disputed
1mo ago

Site isolation issue in the WebExtensions component

Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.22%via NVD
CVE-2026-74934High· 7.5
1mo ago

Site isolation issue in the Graphics: CanvasWebGL component

Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.21%via NVD
CVE-2026-63641Low
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equival…

▾ Sunlitmagicmirror · magicmirrorEPSS 0.43%via NVD
CVE-2026-50138High· 8.1
1mo ago

goshs is a SimpleHTTPServer written in Go

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP po…

▾ Twilightgoshs · goshs.de/goshs/v2EPSS 0.38%via NVD
CVE-2026-68004Critical· 9.8PoC
1mo ago

An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_ap…

An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_ap…

▾ AbyssalEPSS 0.79%via NVD
CVE-2026-19918Medium· 6.3
1mo ago

A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3

A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-72837High· 8.8
1mo ago

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files be…

▾ TwilightEPSS 0.56%via NVD
CVE-2026-69414High· 7.8PoC
1mo ago

Microsoft Defender Elevation of Privilege Vulnerability

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;.

▾ MidnightMicrosoft · Microsoft Malware Protection EngineEPSS 0.33%via CVEORG
CVE-2026-73664None
1mo ago

FreePBX is an open source IP PBX

FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/asterisk/.ssh/authorized_keys for the ast…

▾ SunlitEPSS 0.51%via NVD
CVE-2026-73626High· 7.5⚖ disputed
1mo ago

JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install()

JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/bloc…

▾ Twilightjupyterlab · jupyterlabEPSS 0.36%via NVD
CVE-2026-54526High
1mo ago

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

▾ Twilightargoproj · github.com/argoproj/argo-workflows/v4EPSS 0.55%via GHSA
CVE-2026-72693High· 7.8
1mo ago

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc…

▾ TwilightRed Hat · kbdEPSS 0.16%via NVD
CWE-284 vulnerabilities (CVEs) — page 24 · VulnSea