CWE-285
CVEs classified under CWE-285, newest first.
247 CVEsRSS
CVE-2026-16224Medium· 4.3A vulnerability was identified in jxxghp MoviePilot up to 2.13.5
A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote explo…
CVE-2026-16217Medium· 6.3A security vulnerability has been detected in guohongze adminset up to 0.61
A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the a…
CVE-2026-16214Medium· 6.3A vulnerability was identified in geex-arts django-jet up to 1.0.8
A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the component Dashboard Module. Such manipulation leads to authorization bypass. The attack can be…
CVE-2026-16200High· 7.3A vulnerability has been found in zevorn rt-claw up to 0.2.0
A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. The manipulation leads to incorrect authorization. Remote expl…
CVE-2026-16199Medium· 6.3A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3
A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The att…
CVE-2026-16195Medium· 6.3A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect au…
CVE-2026-16126High· 7.3A vulnerability was determined in zevorn rt-claw up to 0.2.0
A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm/swarm.c of the component Swarm RPC Receiver. This manipulation causes incorrect authori…
CVE-2026-16122Medium· 4.3A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2
A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results…
CVE-2026-16121Medium· 6.3A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2
A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the atta…
CVE-2026-16119Medium· 6.3A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2
A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in i…
CVE-2024-58367NoneSurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized field values through various query techniques
SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized field values through various query techniques. Attackers can exploi…
CVE-2026-16075Medium· 4.3A flaw has been found in AstrBotDevs AstrBot up to 4.25.5
A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing Endpoint. This manipulati…
GHSA-x8mg-6r4p-87pfHighArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
CVE-2026-50346High· 7.8Netlogon RPC Elevation of Privilege Vulnerability
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50344High· 7.8Windows OLE Elevation of Privilege Vulnerability
Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.
CVE-2026-54121High· 8.8PoCActive Directory Certificate Services Elevation of Privilege Vulnerability
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
CVE-2026-58277High· 8.8Microsoft SharePoint Elevation of Privilege Vulnerability
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-58540High· 7.8Windows Installer Elevation of Privilege Vulnerability
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-58631High· 7.8Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
CVE-2026-49170High· 7.8Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
CVE-2026-15516Medium· 5.6A vulnerability was detected in MacCMS Pro up to 2022.1000.3005
A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. …
CVE-2026-15510Medium· 6.3A vulnerability was found in Leantime up to 3.8.0
A vulnerability was found in Leantime up to 3.8.0. Affected is the function Setting::saveSetting of the component API. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been made…
CVE-2026-15509Medium· 6.3A vulnerability has been found in Leantime up to 3.8.0
A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be ca…
CVE-2026-56313High· 8.1Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations
Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.up…
CVE-2026-56241High· 8.3Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cle…
Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cle…
CVE-2026-15499Medium· 6.3A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2
A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is the function FutureTaskTool.call of the file astrbot/core/tools/cron_tools.py of the component Scheduled Task Handler. Performing a manipulation of the …
CVE-2026-15474Medium· 4.3A security flaw has been discovered in Eleveo Call Recording Software 9.7.0
A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown function of the file /callrec/audio.jsp of the component Call Recording Handler. The manipulation of the argument callId results in impro…
CVE-2026-15473Medium· 6.3A vulnerability was identified in Eleveo Call Recording Software 9.7.0
A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authori…
CVE-2026-15472Medium· 4.3A vulnerability was determined in Eleveo Call Recording Software 9.7.0
A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to improper authorization. The attack can be ex…
CVE-2026-15471Medium· 4.3A vulnerability was found in Eleveo Call Recording Software 9.7.0
A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper authorization. Remote exploitation of the attack is po…