VulnSea

CWE-441

CVEs classified under CWE-441, newest first.

65 CVEsRSS

CVE-2026-69399Critical· 10.0
5d ago

Azure Arc Elevation of Privilege Vulnerability

Azure Arc Elevation of Privilege Vulnerability

MidnightMicrosoft · Azure ARCEPSS 0.49%via NVD
CVE-2026-50022Medium· 5.8
5d ago

Metacat is data repository software that helps researchers preserve, share, and discover data

Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter through Apache SolrJ from search endpoints such as /d1/mn/v…

SunlitNCEAS · metacatEPSS 0.29%via NVD
CVE-2026-45723Low· 2.7
5d ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClie…

Sunlitsiderolabs · omniEPSS 0.39%via NVD
CVE-2026-61793Medium· 6.9PoC
5d ago

Nuxt OG Image generates OG Images with Vue templates in Nuxt

Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and b…

Twilightnuxt-modules · og-imageEPSS 0.46%via NVD
CVE-2026-86003High· 7.5
6d ago

CoreDNS is a DNS server written in Go

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.M…

Twilightcoredns · corednsEPSS 0.44%via NVD
CVE-2026-91742Medium· 4.8
1w ago

Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic

Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium…

Sunlitgoogle · chromeEPSS 0.19%via NVD
CVE-2026-58739Medium· 6.7
1w ago

In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy

In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede…

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-0183Medium· 4.4
1w ago

In CPM, there is a possible information disclosure due to a confused deputy

In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-56879Medium· 6.7
1w ago

In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy

In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-56922Medium· 6.7
1w ago

In CPM, there is a possible permission bypass due to a confused deputy

In CPM, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-56945High· 7.8
1w ago

In VPU, there is a possible out-of-bounds write due to a confused deputy

In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-56986High· 8.4
1w ago

In multiple files, there is a possible out-of-bounds read due to type confusion

In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-56985High· 8.4
1w ago

In multiple files, there is a possible way to obtain signatures due to type confusion

In multiple files, there is a possible way to obtain signatures due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-58698Medium· 6.7
1w ago

In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy

In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex…

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-56992Medium· 6.7
1w ago

In multiple files, there is a possible permission bypass due to a confused deputy

In multiple files, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-57042Medium· 6.7
1w ago

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy

In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for…

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-81303Medium· 6.3
1w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without valida…

SunlitRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.27%via NVD
CVE-2026-55225High· 8.0
1w ago

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator wat…

Twilightstrimzi · strimzi-kafka-operatorEPSS 0.19%via NVD
CVE-2026-84616Medium· 5.5PoC
1w ago

A type confusion issue was addressed with improved memory handling

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An a…

Twilightapple · ipadosEPSS 0.11%via NVD
CVE-2026-54628High· 8.6PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without …

Midnightjulien040 · anyqueryEPSS 0.34%via NVD
CVE-2026-87453Medium· 5.3⚖ disputed
1w ago

Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page

Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.26%via NVD
CVE-2026-87442Low· 3.1
1w ago

Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page

Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-87582High· 8.3
1w ago

Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secur…

Twilightgoogle · chromeEPSS 0.36%via NVD
CVE-2026-87502Medium· 4.2
1w ago

Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page

Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security se…

Sunlitgoogle · chromeEPSS 0.17%via NVD
CVE-2026-28614High· 7.8
2w ago

In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy

In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-28607High· 7.8
2w ago

In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy

In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-28603High· 7.8
2w ago

In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy

In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-28600High· 7.8
2w ago

In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy

In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-28657High· 7.8
2w ago

In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy

In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. Us…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-28644High· 7.8
2w ago

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User intera…

Twilightgoogle · androidEPSS 0.07%via NVD
CWE-441 vulnerabilities (CVEs) · VulnSea