VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1097 CVEsRSS

CVE-2026-60345High· 7.2
2mo ago

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components)

Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged …

▾ TwilightEPSS 0.49%via NVD
CVE-2026-60344Medium· 5.4
2mo ago

Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll)

Vulnerability in the Oracle HRMS (France) product of Oracle E-Business Suite (component: French HR Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-56746High· 7.5
2mo ago

io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746)

A flaw was found in Netty, a network application framework. A remote attacker can bypass security controls in the `CorsHandler` component by sending a specially crafted request with a null origin header. This bypasses the intended access r…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.41%via CSAF
CVE-2026-58429Medium· 4.9
2mo ago

Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.47%via GHSA
CVE-2026-58437High· 7.1
2mo ago

Gitea: Repository Visibility Manipulation via Git Push Options

Gitea: Repository Visibility Manipulation via Git Push Options

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
CVE-2026-56657Medium· 6.2
2mo ago

Gitea SSH Key Parser Denial of Service

Gitea SSH Key Parser Denial of Service

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.17%via OSV
CVE-2026-58422High
2mo ago

Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.62%via GHSA
CVE-2026-58507Medium· 5.3
2mo ago

Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint

Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.38%via GHSA
CVE-2026-58421High· 7.5
2mo ago

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.58%via GHSA
CVE-2026-16226Medium· 4.7
2mo ago

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack …

▾ SunlitEPSS 0.38%via NVD
CVE-2026-16201Medium· 5.3
2mo ago

A vulnerability was found in zevorn rt-claw up to 0.2.0

A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. The manipulation results in information disclosure. The att…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-16072Medium· 4.9
2mo ago

A flaw was found in the organization management component of Keycloak

A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration …

▾ Sunlitredhat · build_of_keycloakEPSS 0.43%via NVD
CVE-2026-1609High· 8.1
2mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A…

▾ Twilightredhat · build_of_keycloakEPSS 0.56%via NVD
CVE-2026-55548Medium· 4.3
2mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request om…

▾ Sunlitspaceapplications · yamcsEPSS 0.36%via NVD
CVE-2026-20150High· 8.8
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

▾ Twilightcisco · roomosEPSS 0.42%via NVD
CVE-2026-55014High· 7.8
2mo ago

Windows Remote Help Defense Elevation of Privilege Vulnerability

Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows Remote HelpEPSS 0.30%via CVEORG
CVE-2026-47301High· 8.8PoC
2mo ago

Configuration Manager Elevation of Privilege Vulnerability

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Configuration ManagerEPSS 0.78%via CVEORG
CVE-2026-49805High· 7.0
2mo ago

Win32k Elevation of Privilege Vulnerability

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.24%via CVEORG
CVE-2026-50351High· 7.8
2mo ago

Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability

Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-50342High· 8.8
2mo ago

Windows MIDI Service Module Elevation of Privileges Vulnerability

Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.30%via CVEORG
CVE-2026-50325High· 7.0
2mo ago

Win32k Elevation of Privilege Vulnerability

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.24%via CVEORG
CVE-2026-50297High· 7.0
2mo ago

Win32k Elevation of Privilege Vulnerability

Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.24%via CVEORG
CVE-2026-50335High· 7.8
2mo ago

Windows Operating Systems Elevation of Privilege Vulnerability

Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.30%via CVEORG
CVE-2026-50373High· 7.8
2mo ago

Windows Search Service Elevation of Privilege Vulnerability

Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.30%via CVEORG
CVE-2026-50423High· 7.8
2mo ago

Windows Kernel Elevation of Privilege Vulnerability

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.30%via CVEORG
CVE-2026-50418Medium· 5.1
2mo ago

Windows System Secure Feature Bypass Vulnerability

Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.

▾ SunlitMicrosoft · Windows 11 Version 24H2EPSS 0.27%via CVEORG
CVE-2026-50465High· 7.1
2mo ago

Windows DNS Client Tampering Vulnerability

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.30%via CVEORG
CVE-2026-50495Medium· 6.1
2mo ago

DNS Client Tampering Vulnerability

Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.30%via CVEORG
CVE-2026-56157Medium· 5.4
2mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.50%via CVEORG
CVE-2026-58617High· 8.1
2mo ago

M365 Copilot for iOS Elevation of Privilege Vulnerability

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft 365 Copilot for iOSEPSS 0.79%via CVEORG
CWE-284 vulnerabilities (CVEs) — page 30 · VulnSea