CWE-284
CVEs classified under CWE-284, newest first.
1097 CVEsRSS
CVE-2026-46979Medium· 6.5Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces)
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privile…
CVE-2026-54761High· 7.1PoCTraefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
CVE-2026-54010High· 8.3Open WebUI: Forged chat-file link allows cross-user file read and deletion
Open WebUI: Forged chat-file link allows cross-user file read and deletion
CVE-2026-54012High· 7.1Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
CVE-2026-54015Medium· 6.4Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
GHSA-hv7x-3x78-gx53Medium· 7.4n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
CVE-2026-49411Medium· 6.5Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
CVE-2026-52844High· 7.5Caddy: Windows `file_server` path authorization bypass via encoded backslash
Caddy: Windows `file_server` path authorization bypass via encoded backslash
CVE-2026-54305High· 9.9n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
CVE-2026-28699High· 8.1PoCGitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
CVE-2026-41856High· 7.5The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When…
CVE-2026-44249High· 8.1Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation i…
CVE-2026-41837Medium· 5.3Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0…
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0…
CVE-2026-41728High· 7.5Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 throu…
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 throu…
CVE-2026-48034High@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
CVE-2026-45649High· 7.1Office for Android Spoofing Vulnerability
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
CVE-2026-41092High· 7.8Microsoft Kinect Elevation of Privilege Vulnerability
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
CVE-2026-48578High· 7.9Secure Boot Security Feature Bypass Vulnerability
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
CVE-2026-49161High· 7.8Microsoft PC Manager Security Feature Bypass Vulnerability
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
CVE-2026-42829High· 7.8Windows Administrator Protection Secure Feature Bypass Vulnerability
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.
CVE-2026-45654High· 7.9Secure Boot Security Feature Bypass Vulnerability
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-45658High· 7.8Windows BitLocker Security Feature Bypass Vulnerability
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
CVE-2026-41006High· 7.5Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations…
Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations…
CVE-2026-47907High· 8.6Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to exec…
CVE-2026-45284Medium· 4.6Nextcloud is an open source content collaboration platform
Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This is…
CVE-2026-1933High· 7.1A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete re…
CVE-2026-0856High· 7.8Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel)
Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verif…
CVE-2026-39310High· 8.6Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass wh…
CVE-2026-44926High· 8.8InfoScale CmdServer before 7.4.2 mishandles access control.
InfoScale CmdServer before 7.4.2 mishandles access control.
CVE-2026-44007Critical· 9.1vm2 is an open source vm/sandbox for Node.js
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. Wi…