VulnSea

CWE-285

CVEs classified under CWE-285, newest first.

207 CVEsRSS

CVE-2026-94379Medium· 6.9
today

The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths

The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PU…

SunlitMISP · MISPvia NVD
CVE-2026-94152Medium· 4.3
today

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorizatio…

SunlitOmega Solution · FBP Fulfillment by PeopleEPSS 0.22%via NVD
CVE-2026-93961Medium· 5.3
yesterday

A security flaw has been discovered in Dromara UJCMS up to 12.3.1

A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api/UserController.java of the component UserController. Per…

SunlitDromara · UJCMSEPSS 0.42%via NVD
CVE-2026-93955Medium· 4.3
2d ago

A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1

A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component…

Sunlitgrimmory-tools · grimmoryEPSS 0.40%via NVD
CVE-2026-93954Medium· 4.3
2d ago

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of …

Sunlitgrimmory-tools · grimmoryEPSS 0.38%via NVD
CVE-2026-84241High· 8.1
3d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

TwilightIBM · Guardium Data ProtectionEPSS 0.30%via NVD
CVE-2026-84076High· 7.6
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

TwilightIBM · Guardium Data ProtectionEPSS 0.31%via NVD
CVE-2026-84036High· 7.4
3d ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

TwilightIBM · Guardium Data ProtectionEPSS 0.26%via NVD
CVE-2026-77239High· 8.1
3d ago

WACRM is a self-hostable CRM template for WhatsApp

WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes authenticate account viewers but do not enforce the agent role before using a service-role database client that bypa…

TwilightArnasDon · wacrmEPSS 0.28%via NVD
CVE-2026-61833High· 8.1
3d ago

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to th…

Twilightzot · zotregistry.dev/zot/v2EPSS 0.43%via NVD
CVE-2026-10030High· 7.1
3d ago

IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.

IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.

TwilightIBM · MQEPSS 0.23%via NVD
CVE-2026-67102High· 8.1
3d ago

HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged …

HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged …

TwilightHCL Software · HCL BigFix Service ManagementEPSS 0.27%via NVD
CVE-2026-85878Critical· 9.9
3d ago

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure HorizonDBEPSS 0.55%via NVD
CVE-2026-70200Critical· 10.0
4d ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure Logic AppsEPSS 0.58%via NVD
CVE-2026-54551Medium· 4.3
4d ago

WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management

WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.3.0, the authenticated GET /api/v0/ws statistics WebSocket in internal/app/api/v0/handlers/endpoint_websocket.go subs…

Sunlith44z · wg-portalEPSS 0.21%via NVD
CVE-2026-76420Critical· 9.0
5d ago

A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to i…

A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to i…

MidnightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.37%via NVD
CVE-2026-20286Medium· 4.3
5d ago

A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the l…

A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the l…

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.36%via NVD
CVE-2026-20285Medium· 4.3
5d ago

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an aff…

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an aff…

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.36%via NVD
CVE-2026-92087High· 8.1
5d ago

@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard

@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the relation "or" option together with the…

Twilight@fastify/auth · @fastify/authEPSS 0.36%via NVD
CVE-2026-58704High· 8.8CISA KEV0dayPoC
6d ago

In Cellular Modem, there is a possible permission bypass due to a logic error in the code

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…

Abyssalgoogle · androidEPSS 0.21%via NVD
CVE-2026-11934High· 7.2
6d ago

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input.

TwilightIBM · Verify Identity AccessEPSS 0.32%via NVD
CVE-2026-21587High· 7.1
6d ago

This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center

This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to…

TwilightAtlassian · Jira Service Management Data CenterEPSS 0.32%via NVD
CVE-2026-21586High· 7.1
6d ago

This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorizatio…

This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorizatio…

TwilightAtlassian · Confluence Data CenterEPSS 0.32%via NVD
CVE-2026-90858High· 7.3PoC
6d ago

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of …

Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.31%via NVD
CVE-2026-49446Medium· 6.1PoC
6d ago

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tu…

Twilightazukaar · Cosmos-ServerEPSS 0.29%via NVD
CVE-2026-52822Medium· 5.3
6d ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned historical timesheet after…

Sunlitkimai · kimaiEPSS 0.36%via NVD
CVE-2026-52825Medium· 5.3
6d ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the ref…

Sunlitkimai · kimaiEPSS 0.27%via NVD
CVE-2026-52826Medium· 5.3
6d ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the author…

Sunlitkimai · kimaiEPSS 0.26%via NVD
CVE-2026-48717Critical· 9.1
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when an authorization co…

MidnightOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-45048High· 8.5
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries s…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.25%via NVD
CWE-285 vulnerabilities (CVEs) · VulnSea