Skip to main content

CWE archive

CWE-1220 CVEs

Programmatic archive

100 CVEs tagged with CWE-12207 Critical, 39 High, 43 Medium, 11 Low, 0 Unrated.

CVE-2026-16560

Published Jul 22, 2026

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-50502

Published Jul 14, 2026

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

CVSS 8.0 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-50405

Published Jul 14, 2026

Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-56155

Published Jul 14, 2026

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
25
Buzz score
75.0
KEV listed

CVE-2026-49170

Published Jul 14, 2026

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
6
Buzz score
35.5

CVE-2026-14615

Published Jul 3, 2026

A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative services. When FGAP v2 is enabled, the system fails to properly fi…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-9088

Published Jun 5, 2026

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group me…

CVSS 2.7 · Low
evidence mentions
6
Buzz score
29.5

CVE-2021-46747

Published Jun 1, 2026

Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Net…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-2651

Published May 25, 2026

A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization log…

CVSS 9.0 · Critical
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-37981

Published May 19, 2026

A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Ma…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-54518

Published May 15, 2026

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege lev…

CVSS 7.3 · High
evidence mentions
8
Buzz score
42.0

CVE-2024-21962

Published May 15, 2026

Improper Input Validation in the AMD RAID driver could allow an attacker to point to an arbitrary memory location potentially resulting in privilege escalation and arbitrary code…

CVSS 8.6 · High

CVE-2026-40365

Published May 12, 2026

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-40981

Published May 7, 2026

When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GC…

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-40690

Published Apr 24, 2026

The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asse…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-38743

Published Apr 24, 2026

The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance records: a logged-in Airflow user with read access…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-6356

Published Apr 22, 2026

A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to access…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6388

Published Apr 15, 2026

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to by…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2025-20628

Published Apr 7, 2026

An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-39363

Published Apr 7, 2026

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origi…

CVSS 8.2 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort
Showing 1-25 of 100 CVEsPage 1 of 4