VulnSea

CWE-285

CVEs classified under CWE-285, newest first.

247 CVEsRSS

CVE-2026-16224Medium· 4.3
2mo ago

A vulnerability was identified in jxxghp MoviePilot up to 2.13.5

A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote explo…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-16217Medium· 6.3
2mo ago

A security vulnerability has been detected in guohongze adminset up to 0.61

A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the a…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-16214Medium· 6.3
2mo ago

A vulnerability was identified in geex-arts django-jet up to 1.0.8

A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the component Dashboard Module. Such manipulation leads to authorization bypass. The attack can be…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-16200High· 7.3
2mo ago

A vulnerability has been found in zevorn rt-claw up to 0.2.0

A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. The manipulation leads to incorrect authorization. Remote expl…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-16199Medium· 6.3
2mo ago

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The att…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-16195Medium· 6.3
2mo ago

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect au…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-16126High· 7.3
2mo ago

A vulnerability was determined in zevorn rt-claw up to 0.2.0

A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm/swarm.c of the component Swarm RPC Receiver. This manipulation causes incorrect authori…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-16122Medium· 4.3
2mo ago

A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2

A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-16121Medium· 6.3
2mo ago

A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2

A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the atta…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-16119Medium· 6.3
2mo ago

A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2

A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in i…

▾ SunlitEPSS 0.40%via NVD
CVE-2024-58367None
2mo ago

SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized field values through various query techniques

SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized field values through various query techniques. Attackers can exploi…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-16075Medium· 4.3
2mo ago

A flaw has been found in AstrBotDevs AstrBot up to 4.25.5

A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing Endpoint. This manipulati…

▾ SunlitEPSS 0.37%via NVD
GHSA-x8mg-6r4p-87pfHigh
2mo ago

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization

▾ Twilightarcadedb · com.arcadedb:arcadedb-servervia GHSA
CVE-2026-50346High· 7.8
2mo ago

Netlogon RPC Elevation of Privilege Vulnerability

Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-50344High· 7.8
2mo ago

Windows OLE Elevation of Privilege Vulnerability

Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-54121High· 8.8PoC
2mo ago

Active Directory Certificate Services Elevation of Privilege Vulnerability

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.78%via CVEORG
CVE-2026-58277High· 8.8
2mo ago

Microsoft SharePoint Elevation of Privilege Vulnerability

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.94%via CVEORG
CVE-2026-58540High· 7.8
2mo ago

Windows Installer Elevation of Privilege Vulnerability

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via CVEORG
CVE-2026-58631High· 7.8
2mo ago

Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.

▾ Twilightmicrosoft · windows_admin_centerEPSS 0.30%via NVD
CVE-2026-49170High· 7.8
2mo ago

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-15516Medium· 5.6
2mo ago

A vulnerability was detected in MacCMS Pro up to 2022.1000.3005

A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. …

▾ SunlitEPSS 0.44%via NVD
CVE-2026-15510Medium· 6.3
2mo ago

A vulnerability was found in Leantime up to 3.8.0

A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15509Medium· 6.3
2mo ago

A vulnerability has been found in Leantime up to 3.8.0

A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be ca…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-56313High· 8.1
2mo ago

Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations

Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.up…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-56241High· 8.3
2mo ago

Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cle…

Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cle…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-15499Medium· 6.3
2mo ago

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is the function FutureTaskTool.call of the file astrbot/core/tools/cron_tools.py of the component Scheduled Task Handler. Performing a manipulation of the …

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15474Medium· 4.3
2mo ago

A security flaw has been discovered in Eleveo Call Recording Software 9.7.0

A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown function of the file /callrec/audio.jsp of the component Call Recording Handler. The manipulation of the argument callId results in impro…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15473Medium· 6.3
2mo ago

A vulnerability was identified in Eleveo Call Recording Software 9.7.0

A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authori…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15472Medium· 4.3
2mo ago

A vulnerability was determined in Eleveo Call Recording Software 9.7.0

A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be ex…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15471Medium· 4.3
2mo ago

A vulnerability was found in Eleveo Call Recording Software 9.7.0

A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper authorization. Remote exploitation of the attack is po…

▾ SunlitEPSS 0.35%via NVD
CWE-285 vulnerabilities (CVEs) — page 6 · VulnSea