CWE-284
CVEs classified under CWE-284, newest first.
1097 CVEsRSS
CVE-2026-60345High· 7.2Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components)
Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged …
CVE-2026-60344Medium· 5.4Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll)
Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n…
CVE-2026-56746High· 7.5io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746)
A flaw was found in Netty, a network application framework. A remote attacker can bypass security controls in the `CorsHandler` component by sending a specially crafted request with a null origin header. This bypasses the intended access r…
CVE-2026-58429Medium· 4.9Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
CVE-2026-58437High· 7.1Gitea: Repository Visibility Manipulation via Git Push Options
Gitea: Repository Visibility Manipulation via Git Push Options
CVE-2026-56657Medium· 6.2Gitea SSH Key Parser Denial of Service
Gitea SSH Key Parser Denial of Service
CVE-2026-58422HighGitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-58507Medium· 5.3Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
CVE-2026-58421High· 7.5Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-16226Medium· 4.7A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack …
CVE-2026-16201Medium· 5.3A vulnerability was found in zevorn rt-claw up to 0.2.0
A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. The manipulation results in information disclosure. The att…
CVE-2026-16072Medium· 4.9A flaw was found in the organization management component of Keycloak
A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration …
CVE-2026-1609High· 8.1A flaw was found in Keycloak
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A…
CVE-2026-55548Medium· 4.3Yamcs is a mission control framework
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request om…
CVE-2026-20150High· 8.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…
CVE-2026-55014High· 7.8Windows Remote Help Defense Elevation of Privilege Vulnerability
Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
CVE-2026-47301High· 8.8PoCConfiguration Manager Elevation of Privilege Vulnerability
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
CVE-2026-49805High· 7.0Win32k Elevation of Privilege Vulnerability
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-50351High· 7.8Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.
CVE-2026-50342High· 8.8Windows MIDI Service Module Elevation of Privileges Vulnerability
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-50325High· 7.0Win32k Elevation of Privilege Vulnerability
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-50297High· 7.0Win32k Elevation of Privilege Vulnerability
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-50335High· 7.8Windows Operating Systems Elevation of Privilege Vulnerability
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
CVE-2026-50373High· 7.8Windows Search Service Elevation of Privilege Vulnerability
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CVE-2026-50423High· 7.8Windows Kernel Elevation of Privilege Vulnerability
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50418Medium· 5.1Windows System Secure Feature Bypass Vulnerability
Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-50465High· 7.1Windows DNS Client Tampering Vulnerability
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
CVE-2026-50495Medium· 6.1DNS Client Tampering Vulnerability
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
CVE-2026-56157Medium· 5.4Microsoft SharePoint Server Spoofing Vulnerability
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-58617High· 8.1M365 Copilot for iOS Elevation of Privilege Vulnerability
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.