VulnSea

CWE-285

CVEs classified under CWE-285, newest first.

247 CVEsRSS

CVE-2026-15470Medium· 4.3
2mo ago

A vulnerability has been found in Eleveo Call Recording Software 9.7.0

A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functionality of the file /callrec/group.jsp. Such manipulation leads to improper authorization. The attack may be launched re…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-56240Medium· 4.3
2mo ago

Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates

Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the diverge…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-55664Medium· 4.3
2mo ago

Grist is spreadsheet software using Python as its formula language

Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table and column metadata without applying the document's access rules and did not check that the requested section was act…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-15376Medium· 6.3
2mo ago

A vulnerability was found in Eleveo Call Recording Software 9.7.0

A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. The attack can be launched remotely. Th…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15318Medium· 6.3
2mo ago

A weakness has been identified in Sipeed PicoClaw up to 0.2.9

A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqtt.go of the component MQTT Channel Handler. This manipulation of the argument client_id …

▾ SunlitEPSS 0.37%via NVD
CVE-2026-49977Medium· 4.3
2mo ago

tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies

tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies

▾ Sunlittarteaucitronjs · tarteaucitronjsEPSS 0.35%via GHSA
CVE-2026-15191Medium· 6.3
2mo ago

A flaw has been found in mettle sendportal up to 3.0.1

A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. Executing a…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-55212High· 7.1
2mo ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, the Studio API class definition creation endpoint POST /pimcore-studio/api/class/definition/configuration-view/detail/create is guarded by t…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-58252Medium· 6.5
2mo ago

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user could receive messages on denied subjects when a wildcard subscription overlapp…

▾ Sunlitlinuxfoundation · nats-serverEPSS 0.46%via NVD
CVE-2026-58251Medium· 6.5
2mo ago

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user with subscription deny permissions could bypass a plain subject deny rule by us…

▾ Sunlitlinuxfoundation · nats-serverEPSS 0.46%via NVD
GHSA-p2fr-6hmx-4528Medium· 6.4
2mo ago

@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators

@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators

▾ Sunlitbetter-auth · @better-auth/oauth-providervia GHSA
CVE-2026-55077High· 7.2
2mo ago

Coder: User-admin role can reset owner account password

Coder: User-admin role can reset owner account password

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.61%via GHSA
CVE-2026-55428High· 8.2
2mo ago

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.40%via GHSA
CVE-2026-57983High· 8.7
2mo ago

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.65%via CVEORG
CVE-2026-58284High· 8.3
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.56%via CVEORG
CVE-2026-14608Medium· 4.3
2mo ago

A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0

A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler.…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-50201Medium· 6.5
2mo ago

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission

▾ SunlitSteeltoe · Steeltoe.Management.EndpointEPSS 0.40%via GHSA
CVE-2026-50279High
2mo ago

Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap

Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap

▾ Twilightcraftcms · craftcms/cmsEPSS 0.36%via GHSA
GHSA-q4rm-m6xh-5pv7Medium· 4.3
2mo ago

Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API

Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API

▾ Sunlitfroxlor · froxlor/froxlorvia GHSA
GHSA-f82j-v89j-mf86Medium· 4.3
2mo ago

SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission

SurrealDB: `RELATE` overwrites existing edge records without `UPDATE` permission

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-49997Medium· 5.4
2mo ago

SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted

SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted

▾ Sunlitsurrealdb · surrealdbEPSS 0.35%via GHSA
CVE-2026-13534Medium· 5.0
3mo ago

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument s…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13524Medium· 5.6
3mo ago

A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6

A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulat…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-13514Low· 2.4
3mo ago

A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android

A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.chess. This manipulation causes exposure of backup file t…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-13512Medium· 6.3
3mo ago

A vulnerability was identified in Databend up to 1.2.881 on HTTP

A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handl…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-13511Low· 3.1
3mo ago

A vulnerability was determined in VoltAgent up to 2.1.17

A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the component Memory REST API. Executing a m…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-13508Medium· 5.5
3mo ago

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component Conversation Sharing Handler. This manipulation of the argument conversation.agent caus…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-49338High· 7.1
3mo ago

Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)

Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)

▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.29%via GHSA
CVE-2026-46700Medium· 4.3
3mo ago

@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets

@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets

▾ Sunlitactual-app · @actual-app/sync-serverEPSS 0.34%via GHSA
CVE-2026-12797Medium· 6.3
3mo ago

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

▾ Sunlitlitellm · litellmEPSS 0.40%via OSV
CWE-285 vulnerabilities (CVEs) — page 7 · VulnSea