VulnSea

CWE-285

CVEs classified under CWE-285, newest first.

210 CVEsRSS

CVE-2026-80436High· 8.5
1w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.

Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.27%via NVD
CVE-2026-85543Medium· 4.3PoC
1w ago

Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.

Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.

TwilightHikvision · Wi-Fi series cameraEPSS 0.20%via NVD
CVE-2026-21097Medium· 6.7⚖ disputed
1w ago

Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

Sunlitsamsung · androidEPSS 0.12%via NVD
CVE-2026-86804Medium· 5.3
1w ago

A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10

A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. The man…

Sunlitseakee · CPA-Manager-PlusEPSS 0.38%via NVD
CVE-2026-58611High· 7.8
1w ago

Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · xbox_gaming_servicesEPSS 0.21%via NVD
CVE-2026-86277High· 7.3PoC
2w ago

A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0

A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypas…

MidnightSourceCodester · Syllabus-Aligned Learning Management & Examination SystemEPSS 0.30%via NVD
CVE-2026-86263High· 7.3PoC
2w ago

A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the c…

Midnightsfturing · hosp_orderEPSS 0.41%via NVD
CVE-2026-86262High· 7.3PoC
2w ago

A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderCon…

Midnightsfturing · hosp_orderEPSS 0.41%via NVD
CVE-2026-86261High· 7.3PoC
2w ago

A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Ord…

Midnightsfturing · hosp_orderEPSS 0.41%via NVD
CVE-2026-86283High· 7.1PoC
2w ago

MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL)

MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action corr…

MidnightMISP · MISPEPSS 0.23%via NVD
CVE-2026-86212Medium· 4.3PoC
2w ago

A vulnerability has been found in Open5GS 2.7.7/2.8.0

A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has…

TwilightEPSS 0.28%via NVD
CVE-2026-86183Medium· 5.3PoC
2w ago

A vulnerability was identified in diem-project diem up to 5.1.3

A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the arg…

Twilightdiem-project · diemEPSS 0.33%via NVD
CVE-2026-85638High· 7.3PoC
2w ago

A weakness has been identified in jofpin trape 2.0

A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit h…

Midnightjofpin · trapeEPSS 0.30%via NVD
CVE-2026-18175High· 8.1
2w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.

Twilightibm · iEPSS 0.19%via NVD
CVE-2026-17483Medium· 4.3
2w ago

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.

Sunlitibm · db2_mirror_for_iEPSS 0.15%via NVD
CVE-2026-75165Medium· 6.5
2w ago

An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are n…

An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are n…

SunlitEPSS 0.41%via NVD
CVE-2026-85381Medium· 5.3PoC
2w ago

A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930

A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Home/Controller/ChapterController.c…

Twilightlight0011 · cmsEPSS 0.33%via NVD
CVE-2026-53602Medium
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does n…

Sunlitforgekeep · github.com/forgekeep/nebula-meshEPSS 0.22%via NVD
CVE-2026-85378High· 7.3PoC
2w ago

light0011 cms Chapter Controller ChapterController.class.php _initialize authorization

A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/Chapte…

Midnightlight0011 · cmsEPSS 0.30%via CVEORG
CVE-2026-50554Medium· 5.3
2w ago

Note Mark is an open-source note-taking application

Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the request is ?deleted=true, the service runs the …

Sunlitenchant97 · github.com/enchant97/note-mark/backendEPSS 0.24%via NVD
CVE-2026-79989None
2w ago

The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session

The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s acco…

SunlitEPSS 0.31%via NVD
CVE-2026-82553Medium· 6.3
3w ago

A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5

A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is the function mysqli_query of the file student_dashboard.php of the component Student Dashboard.…

SunlitEPSS 0.21%via NVD
CVE-2026-82658Medium· 4.3
3w ago

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships

Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authori…

SunlitEPSS 0.18%via NVD
CVE-2026-50152Critical· 9.1
3w ago

Ceph is an open-source distributed storage platform providing object, block, and file storage

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, al…

MidnightEPSS 0.16%via NVD
CVE-2026-54766Medium
3w ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation in pkg/models/project_duplicate.go allows an authenticated user who can read a source project to place its duplica…

Sunlitapi · code.vikunja.io/apiEPSS 0.31%via NVD
CVE-2026-55065High· 8.1
3w ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only a…

Twilightapi · code.vikunja.io/apiEPSS 0.35%via NVD
CVE-2026-55547Medium· 4.3
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.jav…

Sunlityamcs · org.yamcs:yamcs-coreEPSS 0.25%via NVD
CVE-2026-16279Critical· 9.3
3w ago

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

MidnightDassault Systèmes · 3DSwymerEPSS 0.25%via NVD
CVE-2026-62249Medium· 4.3
3w ago

Weblate is a web-based continuous localization platform used to manage software translations

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project can retrieve the change history of restricted components in that pr…

SunlitEPSS 0.18%via NVD
CVE-2026-35445High
3w ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated b…

Twilightwinter · winter/wn-backend-moduleEPSS 0.25%via NVD
CWE-285 vulnerabilities (CVEs) — page 3 · VulnSea