Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,461 CVEs tagged with CWE-285124 Critical, 395 High, 654 Medium, 288 Low, 0 Unrated.

CVE-2026-14538

Published Jul 31, 2026

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authe…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48499

Published Jul 30, 2026

Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach r…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-23981

Published Jul 30, 2026

An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updat…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-41187

Published Jul 30, 2026

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and thei…

CVSS 6.2 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-66488

Published Jul 29, 2026

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-18207

Published Jul 29, 2026

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of a unique identifier. An attack…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47726

Published Jul 28, 2026

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGetAuditLog does no admin check.…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-61487

Published Jul 28, 2026

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-64711

Published Jul 27, 2026

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app m…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-43792

Published Jul 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-43775

Published Jul 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to access sensitive user dat…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-43756

Published Jul 27, 2026

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensiti…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-64642

Published Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built w…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-17531

Published Jul 27, 2026

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Un…

CVSS 1.3 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-17530

Published Jul 27, 2026

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/ast…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-17529

Published Jul 27, 2026

A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument r…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-17434

Published Jul 26, 2026

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. E…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-17433

Published Jul 26, 2026

A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MC…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-62835

Published Jul 24, 2026

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56160

Published Jul 24, 2026

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-62563

Published Jul 21, 2026

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily e…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62444

Published Jul 21, 2026

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Ea…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-61082

Published Jul 21, 2026

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability all…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-60957

Published Jul 21, 2026

Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15.…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 1,461 CVEsPage 1 of 59