VulnSea

CWE-602

CVEs classified under CWE-602, newest first.

17 CVEsRSS

CVE-2026-82189High· 8.7
1w ago

Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue…

Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue…

Twilightj2commerce.com · J2Store extension for JoomlaEPSS 0.25%via NVD
CVE-2026-54047Critical· 9.2
1w ago

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies …

MidnightLaciSynchroni · serverEPSS 0.23%via NVD
CVE-2026-89175Medium· 5.3
1w ago

Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability

Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system confi…

SunlitKingdom Communication Associated · EH3040EPSS 0.32%via NVD
CVE-2026-84841High· 7.3
2w ago

A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0

A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched remotely. The expl…

TwilightEPSS 0.31%via NVD
CVE-2026-54553Medium· 5.4
3w ago

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Sunlitstarlette-admin · starlette-adminEPSS 0.34%via OSV
CVE-2026-73267High· 7.7
1mo ago

A flaw was found in the clusterclaims-controller component of multicluster engine (MCE)

A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This all…

TwilightRed Hat · multicluster-engine/clusterclaims-controller-rhel9EPSS 0.46%via NVD
CVE-2026-45274Medium· 6.9PoC
1mo ago

MyBooks is anebook management web server also known as Talebook

MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserver/handlers/user.py does not enforce the ALLOW_REGISTER configuration flag, even though …

TwilightPoxenStudio · talebookEPSS 0.67%via NVD
CVE-2026-73627High· 7.1
1mo ago

JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass

JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules…

TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.25%via NVD
CVE-2026-65938Medium· 4.3
1mo ago

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

SunlitEPSS 0.16%via NVD
CVE-2026-72867Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a dire…

MidnightEPSS 0.49%via NVD
GHSA-h5v5-8746-g7mmMedium
2mo ago

JupyterLab PluginManager lock-rule enforcement bypass

JupyterLab PluginManager lock-rule enforcement bypass

Sunlitjupyterlab · jupyterlabvia OSV
CVE-2026-56693Medium· 5.5
3mo ago

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invok…

Sunlitnanocoai · nanoclawEPSS 0.17%via NVD
CVE-2026-42266High· 8.8
4mo ago

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_…

Twilightjupyter · jupyterlabEPSS 0.63%via NVD
CVE-2026-5901Medium· 6.5
5mo ago

Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions for cookie modification via a crafted Ch…

Insufficient policy enforcement in DevTools in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to bypass enterprise host restrictions for cookie modification via a crafted Ch…

Sunlitgoogle · chromeEPSS 0.14%via NVD
CVE-2026-30783Critical· 9.8
6mo ago

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated …

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated …

MidnightEPSS 0.38%via NVD
CVE-2025-4527Low· 3.7
1y ago

A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21

A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server…

Sunlitdigitro · ngc_explorerEPSS 0.59%via NVD
CVE-2023-42787Medium· 6.5
2y ago

A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access …

A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access …

Sunlitfortinet · fortianalyzerEPSS 1.4%via NVD
CWE-602 vulnerabilities (CVEs) · VulnSea