Vulnerabilities (CVE)

Filtered by CWE-284
Total 5364 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-43590 1 Microsoft 4 Visual C\+\+ Redistributable, Visual Studio 2017, Visual Studio 2019 and 1 more 2026-07-07 N/A 7.8 HIGH
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
CVE-2026-26145 1 Microsoft 1 Azure Synapse 2026-07-07 N/A 4.8 MEDIUM
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
CVE-2026-58286 1 Microsoft 1 Edge Chromium 2026-07-07 N/A 8.1 HIGH
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-14792 2026-07-07 6.4 MEDIUM 6.5 MEDIUM
A security vulnerability has been detected in Formbricks 5.0.0. This impacts an unknown function of the file apps/web/modules/survey/link/actions.ts of the component Survey Handler. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. Upgrading to version 5.1.0-rc.1 will fix this issue. The identifier of the patch is af6023b5ac3b030ffcea24fac799f76f3e3512c6. You should upgrade the affected component.
CVE-2026-14775 2026-07-07 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the affected product appears to have a typo in it.
CVE-2026-22555 2026-07-06 N/A 8.1 HIGH
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
CVE-2026-54407 1 Ui 1 Unifi Protect 2026-07-06 N/A 8.6 HIGH
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.
CVE-2026-55114 1 Ui 1 Unifi Network Application 2026-07-06 N/A 8.8 HIGH
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
CVE-2026-55118 1 Ui 1 Unifi Network Application 2026-07-06 N/A 8.3 HIGH
A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
CVE-2026-58282 1 Microsoft 1 Edge Chromium 2026-07-06 N/A 8.1 HIGH
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20706 2026-07-06 N/A 9.1 CRITICAL
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
CVE-2025-71380 2026-07-06 N/A 8.8 HIGH
The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service disruption, or complete system compromise.
CVE-2026-58422 2026-07-06 N/A 9.8 CRITICAL
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CVE-2026-58421 2026-07-06 N/A 7.5 HIGH
Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-27779 2026-07-06 N/A 7.5 HIGH
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
CVE-2026-28699 2026-07-06 N/A 8.1 HIGH
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
CVE-2026-9085 2026-07-06 N/A 8.8 HIGH
Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Control allows DNS Spoofing. This issue affects Pardus-Parental-Control: from <=0.5.1 before 0.7.0.
CVE-2026-14776 2026-07-06 6.5 MEDIUM 6.3 MEDIUM
A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. Performing a manipulation results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The name of the affected product appears to have a typo in it.
CVE-2026-14736 2026-07-06 7.5 HIGH 7.3 HIGH
A vulnerability was found in Ruijie RG-UAC up to 1.0-R1.8.2.p5. The impacted element is an unknown function of the file user_auth_commit.php. Performing a manipulation of the argument upload_image results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
CVE-2026-14698 2026-07-06 6.5 MEDIUM 6.3 MEDIUM
A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown function of the file upload_files.php. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.