Threats Tagged 'cwe-281'
View all threats tagged with 'cwe-281'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-281'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-82964 is a high-severity vulnerability in Gen Digital's Avast security products affecting versions prior to 26.8. It involves improper preservation of permissions in the Avast sandbox minifilter driver on Windows, allowing a local low-privileged attacker inside the sandbox to escape file isolation and escalate privileges to SYSTEM. The flaw arises because the driver fails to correctly apply the original security descriptor when virtualizing files, resulting in permissive permissions on virtualized copies. This enables a sandboxed process to rewrite security descriptors, access sensitive files like the SAM database, extract NTLM password hashes, and execute code with SYSTEM privileges. Join the discussion | CVE Database V5 | 09/16/2026, 14:01:47 UTC Added: 09/16/2026, 14:32:18 UTC |
0 The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bits. Where extraction is performed by a privileged user, this may allow a local actor to obtain the privileges of the extracting process. This vulnerability (CVE-2026-88922) is fixed in go-getter 1.8.9 and 2.2.4. Join the discussion | CVE Database V5 | 09/15/2026, 19:45:07 UTC Added: 09/15/2026, 19:47:09 UTC |
Gitea contains a vulnerability in its API path for changing repository visibility from public to private. When this change is made via the REST API, stale watch records are not cleared, allowing users who lost access to still see metadata of the now-private repository in their subscription list. This leads to exposure of repository metadata and inflated watcher counts. The issue affects versions from v1.25.4 up to but not including v1.27.0. The severity is medium with limited confidentiality impact and no integrity or availability impact. Join the discussion | GCVE Database | 08/13/2026, 16:44:58 UTC Added: 07/22/2026, 00:11:14 UTC |
This update includes the following RPMs: python3.13: * python3.13-3.13.15-1.hum1 (aarch64, x86_64) * python3.13-debug-3.13.15-1.hum1 (aarch64, x86_64) * python3.13-devel-3.13.15-1.hum1 (aarch64, x86_64) * python3.13-freethreading-3.13.15-1.hum1 (aarch64, x86_64) * python3.13-freethreading-debug-3.13.15-1.hum1 (aarch64, x86_64) * python3.13-idle-3.13.15-1.hum1 (aarch64, x86_64) * python3.13-libs-3.13.15-1.hum1 (aarch64, x86_64) * python3.13-test-3.13.15-1.hum1 (aarch64, x86_64) * python3.13-tkinter-3.13.15-1.hum1 (aarch64, x86_64) * python3.13-3.13.15-1.hum1.src (src) Security Fix(es): python3.13: * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-15308 * CVE-2026-4360 * CVE-2026-6879 Join the discussion | GCVE Database | 08/13/2026, 12:19:42 UTC Added: 07/30/2026, 05:46:50 UTC |
0 CVE-2025-14779 is a vulnerability in WSO2 Identity Server's Secret Type Management REST API where the deletion of a secret type does not properly enforce organizational boundaries. This flaw allows the deletion cascade to remove secrets across all organizations, not just the intended one. Exploitation requires delete permissions on the Secret Type Management REST API, which are typically restricted to administrators. The vulnerability can lead to unintended secret deletions, causing configuration failures, service interruptions, and denial-of-service conditions. The CVSS score is 3.8, indicating a low severity impact. Join the discussion | CVE Database V5 | 08/06/2026, 07:33:10 UTC Added: 08/06/2026, 08:11:46 UTC |
The RHTAS Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21 Join the discussion | GCVE Database | 07/16/2026, 11:19:42 UTC Added: 07/21/2026, 20:03:21 UTC |
0 The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): * golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835) * golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/09/2026, 18:56:09 UTC Added: 07/10/2026, 09:24:17 UTC |
When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer nodes before beeing deemed to be over quota. Join the discussion | CVE Database V5 | 07/09/2026, 14:48:56 UTC Added: 07/09/2026, 15:33:27 UTC |
0 The RHTAS Policy Controller Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20, 4.21, 4.22 Join the discussion | GCVE Database | 07/09/2026, 13:43:04 UTC Added: 07/10/2026, 09:24:17 UTC |
0 Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1. Join the discussion | CVE Database V5 | 07/08/2026, 20:22:16 UTC Added: 07/08/2026, 20:44:01 UTC |
Showing 1 to 10 of 43 results