Vulnerabilities (CVE)

Filtered by CWE-284
Total 7909 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-9517 2026-07-23 7.5 HIGH 7.3 HIGH
A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-9421 2026-07-23 7.5 HIGH 7.3 HIGH
A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File Handler. This manipulation causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-9489 2026-07-23 N/A N/A
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM privileges and to delete arbitrary files with SYSTEM privileges. By leveraging this, an attacker can execute arbitrary code on the target system with elevated privileges.
CVE-2026-41728 1 Vmware 1 Spring Data Rest 2026-07-23 N/A 7.5 HIGH
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.
CVE-2026-46695 2026-07-23 N/A 10.0 CRITICAL
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the directory in rw mode, thereby gaining write access to that directory. This allows malicious code to perform arbitrary write operations on directories that should be read-only. This issue has been patched in version 0.9.0.
CVE-2026-36720 2026-07-23 N/A 8.1 HIGH
Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.
CVE-2026-39169 2026-07-23 N/A 7.5 HIGH
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
CVE-2026-41856 1 Vmware 1 Spring For Graphql 2026-07-23 N/A 7.5 HIGH
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.
CVE-2026-41837 1 Vmware 1 Spring Data Rest 2026-07-23 N/A 5.3 MEDIUM
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.
CVE-2026-45658 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-07-23 N/A 7.8 HIGH
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
CVE-2026-49161 1 Microsoft 1 Pc Manager 2026-07-23 N/A 7.8 HIGH
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
CVE-2026-11621 2026-07-23 5.8 MEDIUM 4.7 MEDIUM
A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /admin/dcat-api/editor-md/upload of the component User Setting Page. This manipulation of the argument editormd-image-file causes unrestricted upload. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-41092 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-07-23 N/A 7.8 HIGH
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
CVE-2026-41984 2026-07-23 N/A 5.2 MEDIUM
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
CVE-2026-48578 1 Microsoft 13 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 10 more 2026-07-23 N/A 7.9 HIGH
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
CVE-2026-41985 2026-07-23 N/A 5.1 MEDIUM
UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
CVE-2026-45654 1 Microsoft 4 Windows 11 24h2, Windows 11 25h2, Windows 11 26h1 and 1 more 2026-07-23 N/A 7.9 HIGH
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-45649 1 Microsoft 3 Excel, Powerpoint, Word 2026-07-23 N/A 7.1 HIGH
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
CVE-2026-41847 1 Vmware 1 Spring Framework 2026-07-23 N/A 4.8 MEDIUM
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.
CVE-2026-49938 1 Fortinet 1 Fortiportal 2026-07-23 N/A 6.5 MEDIUM
A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here>