VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1097 CVEsRSS

CVE-2026-45086Medium· 5.4
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor w…

▾ Sunlitdecidim-demographics · decidim-demographicsEPSS 0.29%via NVD
CVE-2026-45377Medium· 6.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export owner, but the resul…

▾ Sunlitdecidim-core · decidim-coreEPSS 0.45%via NVD
CVE-2026-66803Critical· 10.0
1mo ago

Azure Cosmos DB Remote Code Execution Vulnerability

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Azure Cosmos DBEPSS 0.90%via CVEORG
CVE-2026-62246High· 8.5
1mo ago

Kamaji is the Hosted Control Plane Manager for Kubernetes

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastor…

▾ TwilightEPSS 0.36%via NVD
CVE-2026-16527High· 7.3
1mo ago

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

▾ TwilightEPSS 0.50%via NVD
CVE-2026-67431High
1mo ago

MCP Ruby SDK: Ruby SSE Session Poisoning

MCP Ruby SDK: Ruby SSE Session Poisoning

▾ Twilightmcp · mcpEPSS 0.48%via GHSA
CVE-2026-64863Critical· 9.1
2mo ago

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

▾ Midnightgoshs · goshs.de/goshs/v2EPSS 0.63%via GHSA
CVE-2026-43763Medium· 5.5
2mo ago

A permissions issue was addressed by removing the vulnerable code

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.8, macOS Sequoia 15.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to read files outside of its …

▾ Sunlitapple · macosEPSS 0.15%via NVD
CVE-2026-43760High· 8.6PoC
2mo ago

An access issue was addressed with improved access restrictions

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

▾ Midnightapple · macosEPSS 0.41%via NVD
CVE-2026-17457Medium· 4.3
2mo ago

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of th…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-17432Medium· 5.0
2mo ago

A vulnerability was detected in NousResearch hermes-agent 2026.6.5

A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. …

▾ SunlitEPSS 0.36%via NVD
CVE-2026-35425High· 8.0
2mo ago

Azure API Management (APIM) Remote Code Execution Vulnerability

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Azure API Management (APIM)EPSS 0.70%via CVEORG
CVE-2026-58630Critical· 10.0
2mo ago

Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure App Service for LinuxEPSS 0.86%via CVEORG
GHSA-rm67-g9ch-vxffHigh· 8.1
2mo ago

Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own

Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own

▾ Twilightpoweradmin · poweradmin/poweradminvia GHSA
GHSA-rvhp-75f6-9jqhLow· 3.3
2mo ago

ImageMagick: Policy Bypass possible with matrix-backed operations

ImageMagick: Policy Bypass possible with matrix-backed operations

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-vghg-5jrg-2398Low· 3.3
2mo ago

ImageMagick: Policy Bypass in script operation due to missing checks

ImageMagick: Policy Bypass in script operation due to missing checks

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-whvh-wf3x-g77jLow
2mo ago

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

▾ Sunlitjupyterlab · jupyterlabvia GHSA
CVE-2026-60163High· 8.4
2mo ago

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin)

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0…

▾ Twilightoracle · mysql_serverEPSS 0.19%via NVD
CVE-2026-60811Medium· 6.3
2mo ago

Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History)

Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi…

▾ Sunlitoracle · e-business_suiteEPSS 0.26%via NVD
CVE-2026-60800High· 7.1
2mo ago

Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench)

Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged a…

▾ Twilightoracle · e-business_suiteEPSS 0.30%via NVD
CVE-2026-60799High· 7.1
2mo ago

Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench)

Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged a…

▾ Twilightoracle · e-business_suiteEPSS 0.30%via NVD
CVE-2026-60772High· 7.1
2mo ago

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components)

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged att…

▾ Twilightoracle · e-business_suiteEPSS 0.28%via NVD
CVE-2026-60771High· 8.1
2mo ago

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows l…

▾ Twilightoracle · e-business_suiteEPSS 0.36%via NVD
CVE-2026-60764High· 8.1
2mo ago

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components)

Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged att…

▾ Twilightoracle · e-business_suiteEPSS 0.36%via NVD
CVE-2026-60708High· 8.1
2mo ago

Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi…

▾ Twilightoracle · e-business_suiteEPSS 0.36%via NVD
CVE-2026-60703High· 7.1
2mo ago

Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attack…

▾ Twilightoracle · interaction_blendingEPSS 0.16%via NVD
CVE-2026-60685Medium· 6.1
2mo ago

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with net…

▾ Sunlitoracle · e-business_suiteEPSS 0.13%via NVD
CVE-2026-60683High· 7.7
2mo ago

Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow…

▾ Twilightoracle · e-business_suiteEPSS 0.35%via NVD
CVE-2026-60681High· 8.8
2mo ago

Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow…

▾ Twilightoracle · e-business_suiteEPSS 0.43%via NVD
CVE-2026-60674High· 8.2
2mo ago

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security)

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability al…

▾ Twilightoracle · business_intelligenceEPSS 0.35%via NVD
CWE-284 vulnerabilities (CVEs) — page 26 · VulnSea