CWE-284
CVEs classified under CWE-284, newest first.
1097 CVEsRSS
CVE-2026-45086Medium· 5.4Decidim is a participatory democracy framework
Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor w…
CVE-2026-45377Medium· 6.5Decidim is a participatory democracy framework
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export owner, but the resul…
CVE-2026-66803Critical· 10.0Azure Cosmos DB Remote Code Execution Vulnerability
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
CVE-2026-62246High· 8.5Kamaji is the Hosted Control Plane Manager for Kubernetes
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastor…
CVE-2026-16527High· 7.3An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
CVE-2026-67431HighMCP Ruby SDK: Ruby SSE Session Poisoning
MCP Ruby SDK: Ruby SSE Session Poisoning
CVE-2026-64863Critical· 9.1goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
CVE-2026-43763Medium· 5.5A permissions issue was addressed by removing the vulnerable code
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.8, macOS Sequoia 15.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to read files outside of its …
CVE-2026-43760High· 8.6PoCAn access issue was addressed with improved access restrictions
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
CVE-2026-17457Medium· 4.3A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1
A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of th…
CVE-2026-17432Medium· 5.0A vulnerability was detected in NousResearch hermes-agent 2026.6.5
A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. …
CVE-2026-35425High· 8.0Azure API Management (APIM) Remote Code Execution Vulnerability
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
CVE-2026-58630Critical· 10.0Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
GHSA-rm67-g9ch-vxffHigh· 8.1Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
GHSA-rvhp-75f6-9jqhLow· 3.3ImageMagick: Policy Bypass possible with matrix-backed operations
ImageMagick: Policy Bypass possible with matrix-backed operations
GHSA-vghg-5jrg-2398Low· 3.3ImageMagick: Policy Bypass in script operation due to missing checks
ImageMagick: Policy Bypass in script operation due to missing checks
GHSA-whvh-wf3x-g77jLowJupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
CVE-2026-60163High· 8.4Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin)
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0…
CVE-2026-60811Medium· 6.3Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History)
Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi…
CVE-2026-60800High· 7.1Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench)
Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged a…
CVE-2026-60799High· 7.1Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench)
Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged a…
CVE-2026-60772High· 7.1Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components)
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged att…
CVE-2026-60771High· 8.1Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows l…
CVE-2026-60764High· 8.1Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components)
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged att…
CVE-2026-60708High· 8.1Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privi…
CVE-2026-60703High· 7.1Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Interaction Blending product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attack…
CVE-2026-60685Medium· 6.1Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with net…
CVE-2026-60683High· 7.7Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow…
CVE-2026-60681High· 8.8Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allow…
CVE-2026-60674High· 8.2Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0 and 26.01.0.0.0. Easily exploitable vulnerability al…