CWE-285
CVEs classified under CWE-285, newest first.
247 CVEsRSS
CVE-2026-15470Medium· 4.3A vulnerability has been found in Eleveo Call Recording Software 9.7.0
A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functionality of the file /callrec/group.jsp. Such manipulation leads to improper authorization. The attack may be launched re…
CVE-2026-56240Medium· 4.3Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates
Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the diverge…
CVE-2026-55664Medium· 4.3Grist is spreadsheet software using Python as its formula language
Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table and column metadata without applying the document's access rules and did not check that the requested section was act…
CVE-2026-15376Medium· 6.3A vulnerability was found in Eleveo Call Recording Software 9.7.0
A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. The attack can be launched remotely. Th…
CVE-2026-15318Medium· 6.3A weakness has been identified in Sipeed PicoClaw up to 0.2.9
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqtt.go of the component MQTT Channel Handler. This manipulation of the argument client_id …
CVE-2026-49977Medium· 4.3tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
CVE-2026-15191Medium· 6.3A flaw has been found in mettle sendportal up to 3.0.1
A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. Executing a…
CVE-2026-55212High· 7.1Pimcore is an Open Source Data & Experience Management Platform
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, the Studio API class definition creation endpoint POST /pimcore-studio/api/class/definition/configuration-view/detail/create is guarded by t…
CVE-2026-58252Medium· 6.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user could receive messages on denied subjects when a wildcard subscription overlapp…
CVE-2026-58251Medium· 6.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain subject deny rule by us…
GHSA-p2fr-6hmx-4528Medium· 6.4@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
CVE-2026-55077High· 7.2Coder: User-admin role can reset owner account password
Coder: User-admin role can reset owner account password
CVE-2026-55428High· 8.2Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
CVE-2026-57983High· 8.7Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-58284High· 8.3Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-14608Medium· 4.3A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler.…
CVE-2026-50201Medium· 6.5Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission
CVE-2026-50279HighCraft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
GHSA-q4rm-m6xh-5pv7Medium· 4.3Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API
Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API
GHSA-f82j-v89j-mf86Medium· 4.3SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission
CVE-2026-49997Medium· 5.4SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted
CVE-2026-13534Medium· 5.0A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7
A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument s…
CVE-2026-13524Medium· 5.6A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6
A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulat…
CVE-2026-13514Low· 2.4A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android
A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.chess. This manipulation causes exposure of backup file t…
CVE-2026-13512Medium· 6.3A vulnerability was identified in Databend up to 1.2.881 on HTTP
A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handl…
CVE-2026-13511Low· 3.1A vulnerability was determined in VoltAgent up to 2.1.17
A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the component Memory REST API. Executing a m…
CVE-2026-13508Medium· 5.5A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28
A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component Conversation Sharing Handler. This manipulation of the argument conversation.agent caus…
CVE-2026-49338High· 7.1Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
CVE-2026-46700Medium· 4.3@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
CVE-2026-12797Medium· 6.3BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints