VulnSea

CWE-425

CVEs classified under CWE-425, newest first.

9 CVEsRSS

CVE-2026-40532Medium· 6.5
4d ago

A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.

A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.

SunlitSynology · DiskStation Manager (DSM)EPSS 0.32%via NVD
CVE-2026-36453High· 7.4
1w ago

Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1

Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.

TwilightRhymix · RhymixEPSS 0.16%via NVD
CVE-2026-19903Medium· 5.3
1mo ago

A vulnerability has been found in SourceCodester Online Clothing Store 1.0

A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote…

SunlitEPSS 0.31%via NVD
CVE-2026-13533Medium· 5.3
2mo ago

A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2

A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or…

SunlitEPSS 0.48%via NVD
CVE-2026-11986Medium· 4.9
3mo ago

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when …

SunlitEPSS 0.30%via NVD
CVE-2026-7500Medium· 5.4
4mo ago

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — including both read and write…

SunlitEPSS 0.23%via NVD
CVE-2026-33217High· 7.1
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing M…

Twilightlinuxfoundation · nats-serverEPSS 0.26%via NVD
CVE-2026-25679High· 7.5
6mo ago

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

Twilightgolang · goEPSS 0.73%via NVD
CVE-2026-0650NonePoC
8mo ago

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware

OpenFlagr versions prior to and including 1.1.18 contain an authentication bypass vulnerability in the HTTP middleware. Due to improper handling of path normalization in the whitelist logic, crafted requests can bypass authentication and…

TwilightEPSS 1.3%via NVD
CWE-425 vulnerabilities (CVEs) · VulnSea