Vulnerabilities (CVE)

Filtered by CWE-269
Total 3403 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-34481 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-10 7.5 HIGH 8.8 HIGH
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. UPDATE August 10, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. This security update changes the Point and Print default behavior; please see KB5005652.
CVE-2021-34477 1 Microsoft 2 .net Education Bundle Sdk Install Tool, .net Install Tool For Extension Authors 2026-08-10 4.6 MEDIUM 7.8 HIGH
Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability
CVE-2021-34471 1 Microsoft 1 Malware Protection Engine 2026-08-10 4.6 MEDIUM 7.8 HIGH
Microsoft Defender Elevation of Privilege Vulnerability
CVE-2021-34461 1 Microsoft 2 Windows 10, Windows Server 2016 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
CVE-2021-34460 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2021-34459 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows AppContainer Elevation Of Privilege Vulnerability
CVE-2021-34456 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2021-34455 1 Microsoft 6 Windows 10, Windows 8.1, Windows Rt 8.1 and 3 more 2026-08-10 4.6 MEDIUM 7.8 HIGH
Windows File History Service Elevation of Privilege Vulnerability
CVE-2021-33751 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2026-08-10 4.6 MEDIUM 7.0 HIGH
Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2021-31961 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2026-08-10 3.6 LOW 6.1 MEDIUM
Windows InstallService Elevation of Privilege Vulnerability
CVE-2026-1728 1 Wso2 4 Api Control Plane, Api Manager, Traffic Manager and 1 more 2026-08-10 N/A 9.8 CRITICAL
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This requires the attacker to already possess a low-privileged user account and be able to obtain a valid token for it.
CVE-2026-54415 2026-08-10 N/A 8.1 HIGH
Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}).
CVE-2024-8424 2026-08-08 N/A N/A
Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions.
CVE-2026-60678 1 Oracle 1 E-business Suite 2026-08-07 N/A 8.8 HIGH
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in takeover of Oracle General Ledger. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2026-44231 1 Bestpractical 1 Request Tracker 2026-08-07 N/A 9.1 CRITICAL
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.
CVE-2026-62515 1 Oracle 1 E-business Suite 2026-08-07 N/A 7.6 HIGH
Vulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Planning Command Center. While the vulnerability is in Oracle Advanced Planning Command Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Planning Command Center accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Planning Command Center accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).
CVE-2026-62493 1 Oracle 1 E-business Suite 2026-08-07 N/A 7.5 HIGH
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2026-62534 1 Oracle 1 Applications Framework 2026-08-06 N/A 8.8 HIGH
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVE-2026-20308 2026-08-06 N/A 4.3 MEDIUM
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.
CVE-2026-62474 1 Oracle 1 Lease And Finance Management 2026-08-06 N/A 6.3 MEDIUM
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Lease Authoring). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Lease and Finance Management accessible data as well as unauthorized read access to a subset of Oracle Lease and Finance Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Lease and Finance Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).