Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

6,206 CVEs tagged with CWE-284790 Critical, 2,189 High, 2,678 Medium, 547 Low, 2 Unrated.

CVE-2026-58043

Published Jul 30, 2026

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-67431

Published Jul 29, 2026

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem does not bin…

CVSS 8.3 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-65888

Published Jul 29, 2026

Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-65887

Published Jul 29, 2026

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to logi…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-65889

Published Jul 29, 2026

Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-65943

Published Jul 29, 2026

Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65884

Published Jul 29, 2026

Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to registe…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-41920

Published Jul 29, 2026

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recomm…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-63236

Published Jul 29, 2026

An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson positio…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-63235

Published Jul 29, 2026

An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login k…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-64863

Published Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and d…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-7362

Published Jul 28, 2026

IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could a…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62427

Published Jul 28, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operati…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18038

Published Jul 28, 2026

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-14926

Published Jul 28, 2026

The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoi…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2021-32084

Published Jul 27, 2026

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints ar…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-64738

Published Jul 27, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-64737

Published Jul 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be abl…

CVSS 8.2 · High
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-64732

Published Jul 27, 2026

This issue was addressed through improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6. An attacker with physical access may be able to access sensitive user…

CVSS 4.6 · Medium
evidence mentions
2
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64723

Published Jul 27, 2026

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user d…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-64702

Published Jul 27, 2026

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-43819

Published Jul 27, 2026

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43779

Published Jul 27, 2026

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to intercept network…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-43763

Published Jul 27, 2026

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to read f…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 6,206 CVEsPage 1 of 249