Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,456 CVEs tagged with CWE-285123 Critical, 395 High, 650 Medium, 288 Low, 0 Unrated.

CVE-2026-18207

Published Jul 29, 2026

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attack…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47726

Published Jul 28, 2026

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGetAuditLog does no admin check.…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-61487

Published Jul 28, 2026

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-64711

Published Jul 27, 2026

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app m…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-43792

Published Jul 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-43775

Published Jul 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to access sensitive user dat…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-43756

Published Jul 27, 2026

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensiti…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-64642

Published Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built w…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-17531

Published Jul 27, 2026

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Un…

CVSS 1.3 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-17530

Published Jul 27, 2026

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/ast…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-17529

Published Jul 27, 2026

A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument r…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-17434

Published Jul 26, 2026

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. E…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-17433

Published Jul 26, 2026

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MC…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-62835

Published Jul 24, 2026

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56160

Published Jul 24, 2026

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-62563

Published Jul 21, 2026

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily e…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62444

Published Jul 21, 2026

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Ea…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-61082

Published Jul 21, 2026

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability all…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-60957

Published Jul 21, 2026

Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15.…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-60911

Published Jul 21, 2026

Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-60886

Published Jul 21, 2026

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily e…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-60844

Published Jul 21, 2026

Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request). Supported versions that are affected are 12.2.3-12.2.15. Easi…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-60842

Published Jul 21, 2026

Vulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitab…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-60152

Published Jul 21, 2026

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Supported versions that are affected are 8.61 and 8.62. Easily…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 1,456 CVEsPage 1 of 59