Skip to main content

CWE archive

CWE-267 CVEs

Programmatic archive

64 CVEs tagged with CWE-2674 Critical, 34 High, 24 Medium, 2 Low, 0 Unrated.

CVE-2026-6816

Published May 28, 2026

An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. This issue affec…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-9560

Published May 26, 2026

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC c…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-29646

Published Apr 20, 2026

In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enable CSR (sie) may be handled inc…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
30.8

CVE-2026-27314

Published Apr 7, 2026

Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate ident…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-14349

Published Feb 13, 2026

Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software Inc. FlexCity/Kiosk allows Accessing Functionality Not Prop…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0945

Published Feb 4, 2026

Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue affects Role Delegation: from 1.3.0 before 1.5.0.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13979

Published Jan 28, 2026

Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23526

Published Jan 21, 2026

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0, users that have the staff status may freely change their…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-53900

Published Nov 29, 2025

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62641

Published Oct 21, 2025

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulne…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62591

Published Oct 21, 2025

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulne…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62590

Published Oct 21, 2025

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulne…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62589

Published Oct 21, 2025

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulne…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62588

Published Oct 21, 2025

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulne…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62587

Published Oct 21, 2025

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.12 and 7.2.2. Easily exploitable vulne…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62480

Published Oct 21, 2025

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Naming Subsystem). The supported version that is affected is 8.8. Easily exploitable…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-62479

Published Oct 21, 2025

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Block Storage). The supported version that is affected is 8.8. Easily exploitable vul…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-62289

Published Oct 21, 2025

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulne…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61754

Published Oct 21, 2025

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily explo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53070

Published Oct 21, 2025

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows high…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-41244

Published Sep 29, 2025

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with V…

CVSS 7.8 · High
evidence mentions
7
Buzz score
57.3
KEV listed
Showing 1-25 of 64 CVEsPage 1 of 3