VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1097 CVEsRSS

CVE-2026-73212None
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without canonicalizing IPv4-compatible, 6to4, a…

▾ SunlitEPSS 0.50%via NVD
CVE-2026-66804High· 7.8PoC
1mo ago

Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 22H2EPSS 0.30%via CVEORG
CVE-2026-65773High· 7.8
1mo ago

Windows Kernel Elevation of Privilege Vulnerability

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.30%via CVEORG
CVE-2026-65675High· 7.1
1mo ago

No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.

No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.

▾ Twilightmicrosoft · github_copilot_chatEPSS 0.64%via NVD
CVE-2026-18951High· 8.8
1mo ago

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with …

▾ TwilightRed Hat · rhoai/odh-training-operator-rhel9EPSS 0.89%via NVD
CVE-2026-72909None
1mo ago

ERPNext is a free and open source Enterprise Resource Planning tool

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply …

▾ SunlitEPSS 0.47%via NVD
CVE-2026-19383Medium· 4.7
1mo ago

A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1

A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulation leads to unre…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-19359Medium· 4.7
1mo ago

A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0

A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls.…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-19358Medium· 6.3
1mo ago

A weakness has been identified in 3CORESec Trapdoor up to 1.2.2

A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was cont…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-19357Medium· 5.3
1mo ago

A security flaw has been discovered in MingSoft MCMS up to 3.0.6

A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attac…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-19356Medium· 5.3
1mo ago

A vulnerability was identified in MingSoft MCMS up to 3.0.6

A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the att…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-12261Medium· 6.5PoC
1mo ago

A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning

A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of packa…

▾ Twilightnltk · nltkEPSS 0.21%via NVD
CVE-2026-19195High· 7.8PoC
1mo ago

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39

A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack ne…

▾ MidnightEPSS 0.16%via NVD
CVE-2026-19193High· 7.8PoC
1mo ago

A flaw has been found in Jiangmin Antivirus 21

A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to…

▾ MidnightEPSS 0.16%via NVD
CVE-2026-66494None
1mo ago

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request

Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla site's database via a single HTTP request. When an adm…

▾ SunlitEPSS 0.50%via NVD
CVE-2026-19192High· 7.8
1mo ago

A vulnerability was detected in DeepCool DisplayService 1.2.12

A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access con…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-65668High· 8.8
1mo ago

Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft Purview eDiscoveryEPSS 0.78%via CVEORG
CVE-2026-56161Critical· 9.6
1mo ago

Azure Logic Apps Information Disclosure Vulnerability

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

▾ MidnightMicrosoft · Azure Logic AppsEPSS 0.69%via CVEORG
CVE-2026-54765Medium
1mo ago

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

▾ Sunlittraefik · github.com/traefik/traefik/v3EPSS 0.35%via GHSA
CVE-2025-70962High· 7.5PoC
1mo ago

Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control

Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to…

▾ MidnightEPSS 0.50%via NVD
CVE-2025-63822High· 8.1
1mo ago

SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control

SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other use…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-70430Low· 2.7
1mo ago

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arb…

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arb…

▾ Sunlitjenkins · jenkinsEPSS 0.31%via NVD
CVE-2026-16102High· 8.1
1mo ago

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to wri…

▾ Twilightredhat · build_of_keycloakEPSS 0.46%via NVD
CVE-2026-20304Critical· 9.9
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that…

▾ MidnightEPSS 0.42%via NVD
CVE-2026-20267Critical· 9.0
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

▾ Midnightcisco · ios_xeEPSS 0.38%via NVD
CVE-2026-71204Medium· 6.2PoC
1mo ago

changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.

changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update.

▾ TwilightEPSS 0.32%via NVD
CVE-2026-70612Medium· 5.4
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sand…

▾ Sunlitelectron · electronEPSS 0.44%via NVD
CVE-2026-70602Medium· 6.6
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. …

▾ Sunlitelectron · electronEPSS 0.26%via NVD
CVE-2026-70481Medium· 5.4PoC
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checki…

▾ Twilightopenwebui · open_webuiEPSS 0.43%via NVD
CVE-2026-70476High· 8.2
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterp…

▾ Twilightflowiseai · flowiseEPSS 0.52%via NVD
CWE-284 vulnerabilities (CVEs) — page 25 · VulnSea