VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1097 CVEsRSS

CVE-2026-53816High· 7.2
2mo ago

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

▾ Twilightopenclaw · openclawEPSS 0.50%via GHSA
GHSA-xww8-gqvh-92x9High· 8.0
2mo ago

OpenClaw: Exec approval display truncation could hide the command being approved

OpenClaw: Exec approval display truncation could hide the command being approved

▾ Twilightopenclaw · openclawvia GHSA
GHSA-qh2f-99mv-mrcfMedium
2mo ago

OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn

OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-2j8v-hwgc-x698High
2mo ago

OpenClaw: Shell wrapper argv could change between approval and execution

OpenClaw: Shell wrapper argv could change between approval and execution

▾ TwilightOpenclaw · Openclawvia GHSA
CVE-2026-53812Medium· 7.7
2mo ago

OpenClaw's browser act interactions could bypass private-network navigation checks

OpenClaw's browser act interactions could bypass private-network navigation checks

▾ Sunlitopenclaw · openclawEPSS 0.39%via GHSA
CVE-2026-53810High· 8.8
2mo ago

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

▾ Twilightopenclaw · openclawEPSS 0.62%via GHSA
GHSA-rggc-m335-3wvjHigh
2mo ago

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-53817High· 8.0
2mo ago

OpenClaw: Control UI locality spoofing could mint a durable admin device token

OpenClaw: Control UI locality spoofing could mint a durable admin device token

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-53814High· 8.4
2mo ago

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority

▾ Twilightopenclaw · openclawEPSS 0.39%via GHSA
GHSA-mhq8-78pj-5j79High· 7.1
2mo ago

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion

▾ Twilightopenclaw · openclawvia GHSA
GHSA-7m8x-qg2j-4m3vHigh· 8.1
3mo ago

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

Fission: MessageQueueTrigger scaler manager materializes Secret values into Deployment envvars and accepts arbitrary user PodSpec

▾ Twilightfission · github.com/fission/fissionvia GHSA
CVE-2026-49822High· 7.7
3mo ago

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

▾ Twilightfission · github.com/fission/fissionEPSS 0.40%via GHSA
CVE-2026-49823High· 7.7
3mo ago

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook

▾ Twilightfission · github.com/fission/fissionEPSS 0.44%via GHSA
CVE-2026-49824High· 8.5
3mo ago

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook

▾ Twilightfission · github.com/fission/fissionEPSS 0.39%via GHSA
CVE-2026-50545Critical· 9.9
3mo ago

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover

▾ Midnightfission · github.com/fission/fissionEPSS 0.52%via GHSA
CVE-2026-50563Critical· 9.9
3mo ago

Fission Container Executor Function PodSpec Injection Leading to Node Escape

Fission Container Executor Function PodSpec Injection Leading to Node Escape

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-50564Critical· 9.9
3mo ago

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape

▾ Midnightfission · github.com/fission/fissionEPSS 0.51%via GHSA
CVE-2026-56290Critical· 9.8CISA KEVPoC
3mo ago

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

▾ Hadaljoomlack · page_builder_ckEPSS 31%via NVD
GHSA-vgrc-hq28-p3xpHigh· 7.4
3mo ago

Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF

Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF

▾ Twilightapernet · github.com/apernet/hysteria/core/v2via GHSA
CVE-2026-53520Medium· 6.5
3mo ago

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing

▾ Sunlitnezhahq · github.com/nezhahq/nezhaEPSS 0.40%via GHSA
CVE-2026-48529Medium· 6.0
3mo ago

GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion

GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion

▾ Sunlitgithub · github.com/github/github-mcp-serverEPSS 0.21%via GHSA
CVE-2026-52810HighPoC
3mo ago

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion

▾ Midnightgogs · gogs.io/gogsEPSS 0.43%via GHSA
CVE-2024-37155Medium· 6.5
3mo ago

OpenCTI May Bypass Introspection Restriction

OpenCTI May Bypass Introspection Restriction

▾ Sunlitpycti · pyctiEPSS 0.46%via GHSA
CVE-2026-31978Medium· 6.5
3mo ago

motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint

motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint

▾ Sunlitmotioneye · motioneyeEPSS 0.42%via GHSA
CVE-2026-50132High· 7.3
3mo ago

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

▾ Twilightbudibase · @budibase/serverEPSS 0.19%via GHSA
CVE-2026-48939Critical· 9.8CISA KEVPoC
3mo ago

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

▾ Hadaljoomlic · icagendaEPSS 20%via NVD
CVE-2026-47647Critical· 9.9
3mo ago

Dynamics 365 Elevation of Privilege Vulnerability

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Dynamics 365EPSS 0.78%via CVEORG
CVE-2026-53843High· 8.8
3mo ago

OpenClaw: Pairing-scoped device session could restore revoked node token authority

OpenClaw: Pairing-scoped device session could restore revoked node token authority

▾ Twilightopenclaw · openclawEPSS 0.49%via GHSA
CVE-2026-55670Low
3mo ago

ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers

ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.36%via GHSA
CVE-2026-53855High· 8.1
3mo ago

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
CWE-284 vulnerabilities (CVEs) — page 32 · VulnSea