VulnSea

CWE-287

CVEs classified under CWE-287, newest first.

455 CVEsRSS

CVE-2026-86709Critical· 9.8
1w ago

The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.

The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.

▾ MidnightEPSS 0.63%via NVD
CVE-2026-86710Critical· 9.8
1w ago

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, includi…

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, includi…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-92578High· 8.1PoC
1w ago

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify()

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attacke…

▾ MidnightWWBN · AVideoEPSS 0.62%via NVD
CVE-2026-92792High· 7.5PoC
1w ago

OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally

OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verific…

▾ MidnightOpenNHP · opennhpEPSS 0.60%via NVD
CVE-2026-92401High· 7.3
1w ago

A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd

A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper aut…

▾ TwilightChangeWeDer · crmEPSS 0.69%via NVD
CVE-2025-43936High· 8.1
1w ago

Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability

Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

▾ Twilightdell · objectscaleEPSS 0.48%via NVD
CVE-2026-19607Medium· 5.3
1w ago

A flaw was found in the first-broker-login flow of the keycloak-services component

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker…

▾ SunlitRed Hat · keycloak-rhel9-containerEPSS 0.51%via NVD
CVE-2026-76187Critical· 9.8
1w ago

Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow

Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts whic…

▾ Midnightapache · apache-airflow-providers-keycloakEPSS 0.98%via NVD
CVE-2026-87217Critical· 9.1
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Midnightoracle · hyperion_financial_managementEPSS 0.43%via NVD
CVE-2026-87188Critical· 9.8
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Midnightoracle · hyperion_financial_managementEPSS 0.51%via NVD
CVE-2026-87184Critical· 9.8
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Midnightoracle · hyperion_financial_managementEPSS 0.59%via NVD
CVE-2026-87176Critical· 9.1
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Midnightoracle · hyperion_financial_managementEPSS 0.43%via NVD
CVE-2026-87175Critical· 9.1
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Midnightoracle · hyperion_financial_managementEPSS 0.43%via NVD
CVE-2026-87173Critical· 9.1
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Midnightoracle · hyperion_financial_managementEPSS 0.43%via NVD
CVE-2026-87170Critical· 9.1
1w ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Midnightoracle · hyperion_financial_managementEPSS 0.43%via NVD
CVE-2026-87129Critical· 9.1
1w ago

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthentic…

▾ Midnightoracle · hyperion_data_relationship_managementEPSS 0.43%via NVD
CVE-2026-87128Critical· 9.1
1w ago

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthentic…

▾ Midnightoracle · hyperion_data_relationship_managementEPSS 0.43%via NVD
CVE-2026-83462Critical· 9.8
1w ago

Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server)

Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated …

▾ MidnightOracle Corporation · Oracle Mobile Application ServerEPSS 0.48%via NVD
CVE-2026-83452Critical· 9.8
1w ago

Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unau…

▾ MidnightOracle Corporation · Oracle Document Management and CollaborationEPSS 0.48%via NVD
CVE-2026-83355Critical· 9.8
1w ago

Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics)

Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthentic…

▾ MidnightOracle Corporation · Oracle Enterprise Manager for Fusion MiddlewareEPSS 0.48%via NVD
CVE-2026-83339Critical· 9.8
1w ago

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle)

Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauth…

▾ Midnightoracle · webcenter_enterprise_captureEPSS 0.51%via NVD
CVE-2026-83327Critical· 9.8
1w ago

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization)

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacke…

▾ MidnightOracle Corporation · Oracle Applications FrameworkEPSS 0.46%via NVD
CVE-2026-83283Critical· 9.8
1w ago

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security)

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthentica…

▾ MidnightOracle Corporation · Oracle Business Intelligence Enterprise EditionEPSS 0.48%via NVD
CVE-2026-83269Critical· 9.8
1w ago

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security)

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthentic…

▾ MidnightOracle Corporation · Oracle BI PublisherEPSS 0.48%via NVD
CVE-2026-83261Critical· 9.8
1w ago

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core)

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network ac…

▾ MidnightOracle Corporation · Oracle Product Lifecycle AnalyticsEPSS 0.48%via NVD
CVE-2026-83232Critical· 9.8
1w ago

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer)

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows una…

▾ MidnightOracle Corporation · Oracle Data IntegratorEPSS 0.48%via NVD
CVE-2026-83202Critical· 9.1
1w ago

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure)

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with networ…

▾ Midnightoracle · siebel_crmEPSS 0.43%via NVD
CVE-2026-83201Critical· 9.1
1w ago

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure)

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with networ…

▾ Midnightoracle · siebel_crmEPSS 0.43%via NVD
CVE-2026-83154Critical· 9.1
1w ago

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI)

Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOA…

▾ Midnightoracle · siebel_crmEPSS 0.43%via NVD
CVE-2026-83151Critical· 9.8
1w ago

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler)

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthentica…

▾ MidnightOracle Corporation · Service Delivery PlatformEPSS 0.48%via NVD
CWE-287 vulnerabilities (CVEs) — page 3 · VulnSea