VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1097 CVEsRSS

CVE-2026-0012Medium· 6.2
7mo ago

In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code

In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User inter…

▾ Sunlitgoogle · androidEPSS 0.11%via NVD
CVE-2026-20736High· 7.5
8mo ago

Gitea does not properly verify repository context when deleting attachments

Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a dif…

▾ Twilightgitea · giteaEPSS 0.44%via NVD
CVE-2026-20912Critical· 9.1
8mo ago

Gitea does not properly validate repository ownership when linking attachments to releases

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to…

▾ Midnightgitea · giteaEPSS 0.46%via NVD
CVE-2026-20897Critical· 9.1
8mo ago

Gitea does not properly validate repository ownership when deleting Git LFS locks

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.

▾ Midnightgitea · giteaEPSS 0.46%via NVD
CVE-2026-20750Critical· 9.1
8mo ago

Gitea does not properly validate project ownership in organization project operations

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.

▾ Midnightgitea · giteaEPSS 0.44%via NVD
CVE-2026-21962Critical· 10.0CISA KEVPoC
8mo ago

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)

Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versio…

▾ Hadaloracle · http_serverEPSS 71%via NVD
CVE-2026-20843High· 7.8
8mo ago

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 3.5%via NVD
CVE-2026-20839Medium· 5.5
8mo ago

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.49%via NVD
CVE-2026-20825Medium· 4.4
8mo ago

Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.

Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.

▾ Sunlitmicrosoft · windows_10_1809EPSS 0.54%via NVD
CVE-2026-0881Critical· 10.0
8mo ago

Sandbox escape in the Messaging System component

Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

▾ Midnightmozilla · firefoxEPSS 0.36%via NVD
CVE-2025-67510Critical· 9.4
9mo ago

Neuron is a PHP framework for creating and orchestrating AI Agents

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is co…

▾ Midnightneuron-ai · neuronEPSS 0.41%via NVD
CVE-2025-64897Medium· 5.6
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized writ…

▾ Sunlitadobe · coldfusionEPSS 0.13%via NVD
CVE-2025-65797Medium· 6.5
9mo ago

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Ser…

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Ser…

▾ Sunlitusememos · memosEPSS 0.28%via NVD
CVE-2025-65795High· 7.5
9mo ago

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.

▾ Twilightusememos · memosEPSS 0.26%via NVD
CVE-2025-65798Medium· 5.4
9mo ago

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

▾ Sunlitusememos · memosEPSS 0.18%via NVD
CVE-2025-65796Medium· 4.3
9mo ago

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

▾ Sunlitusememos · memosEPSS 0.20%via NVD
CVE-2025-66557Medium· 5.4
9mo ago

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.14.6 and 1.15.2, a bug in the permission logic allowed users with "Can share" permissi…

▾ Sunlitnextcloud · deckEPSS 0.28%via NVD
CVE-2025-14052Medium· 6.3
9mo ago

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The manipulation of the argument memberId leads to improper acc…

▾ Sunlityoulai · youlai-mallEPSS 0.26%via NVD
CVE-2025-65097Medium· 6.5
9mo ago

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, an Authenticated User can delete collections belonging to other users by dire…

▾ Sunlitromm.app · rommEPSS 0.21%via NVD
CVE-2025-65096Medium· 4.3
9mo ago

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, users can read private collections / smart collections belonging to other use…

▾ Sunlitromm.app · rommEPSS 0.19%via NVD
CVE-2025-65841Medium· 6.2
9mo ago

Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Support/Aquarius/aquarius.settings using a weak obfuscation scheme

Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Support/Aquarius/aquarius.settings using a weak obfuscation scheme. The password is "encrypted" through predictable byte-su…

▾ Sunlitacustica-audio · aquariusEPSS 0.20%via NVD
CVE-2025-59703Critical· 9.1
10mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamp…

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamp…

▾ Midnightentrust · nshield_5c_firmwareEPSS 0.46%via NVD
CVE-2025-59702High· 7.2
10mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal …

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with elevated privileges to falsify tamper events by accessing internal …

▾ Twilightentrust · nshield_5c_firmwareEPSS 0.31%via NVD
CVE-2025-59697High· 7.2
10mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configurati…

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker to escalate privileges by editing the Legacy GRUB bootloader configurati…

▾ Twilightentrust · nshield_5c_firmwareEPSS 0.31%via NVD
CVE-2025-55749High· 7.5PoC
10mo ago

XWiki is an open-source wiki software platform

XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder.…

▾ Midnightxwiki · xwikiEPSS 1.5%via NVD
CVE-2025-13815Medium· 6.3
10mo ago

A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2

A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestricted upload. The attack may be initia…

▾ Sunlitmogublog_project · mogublogEPSS 0.38%via NVD
CVE-2025-13804Medium· 4.3
10mo ago

A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT

A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/E…

▾ SunlitEPSS 0.26%via NVD
CVE-2025-13785Medium· 4.3
10mo ago

A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5

A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the file /user/profile of the component Image Handler. Such manipulation leads to informatio…

▾ Sunlityungifez · skuulEPSS 0.37%via NVD
CVE-2025-48986High· 8.8
10mo ago

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

▾ Twilightrevive-adserver · revive_adserverEPSS 0.62%via NVD
CVE-2025-56499Medium· 6.5PoC
10mo ago

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.

▾ Twilightmetacubex · mihomoEPSS 0.31%via NVD
CWE-284 vulnerabilities (CVEs) — page 35 · VulnSea