VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

668 CVEsRSS

CVE-2026-84205Medium· 6.5
3w ago

GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the sam…

GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the sam…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-82870Critical· 9.6PoC
3w ago

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing or…

▾ AbyssalToolJet · ToolJetEPSS 0.43%via NVD
CVE-2026-82874Critical· 9.9
3w ago

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across te…

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across te…

▾ MidnightToolJet · ToolJetEPSS 0.44%via NVD
CVE-2026-82873Medium· 5.0
3w ago

ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app def…

ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and export app def…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-82872Critical· 9.1PoC
3w ago

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can create, view, and delete database tables in another w…

▾ AbyssalToolJet · ToolJetEPSS 0.51%via NVD
CVE-2026-82869High· 7.7
3w ago

ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation

ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation. Attackers can …

▾ TwilightEPSS 0.41%via NVD
CVE-2026-50198Medium· 4.3
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to a subscription ID belonging to another u…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-79750High· 7.7
3w ago

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, MCPHub scopes non-admin users to servers they own (…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-72001High· 8.1PoC
3w ago

Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the share-link authentication endpoint tha…

Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the share-link authentication endpoint tha…

▾ MidnightEPSS 0.49%via NVD
CVE-2026-82395Medium
3w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media …

▾ Sunlitsulu · sulu/suluEPSS 0.43%via NVD
CVE-2026-81892High· 8.1
3w ago

EasyAdmin is a fast and modern admin generator for Symfony applications

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuIt…

▾ Twilighteasycorp · easycorp/easyadmin-bundleEPSS 0.45%via NVD
CVE-2026-53552Critical· 9.6
3w ago

Goploy is an open-source automation deployment system

Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id fro…

▾ Midnightzhenorzz · github.com/zhenorzz/goployEPSS 0.35%via NVD
CVE-2026-81200Low· 2.7
4w ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email ad…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email ad…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-80311Medium· 4.3
4w ago

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed por…

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed por…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-82284High· 8.1PoC
1mo ago

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation his…

▾ MidnightQuivrHQ · quivrEPSS 0.30%via NVD
CVE-2026-82283High· 8.1PoC
1mo ago

VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations

VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by s…

▾ MidnightVoltAgent · @voltagent/server-coreEPSS 0.30%via NVD
CVE-2026-82281High· 7.4
1mo ago

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversati…

▾ TwilightEPSS 0.33%via NVD
CVE-2026-82280High· 7.1PoC
1mo ago

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite sy…

▾ MidnightQuivrHQ · quivrEPSS 0.25%via NVD
CVE-2026-82271Medium· 6.5PoC
1mo ago

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename…

▾ TwilightSciPhi-AI · r2rEPSS 0.27%via NVD
CVE-2026-82290Medium· 5.3PoC
1mo ago

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback identifiers, corrupting human-rating …

▾ TwilightChainlit · chainlitEPSS 0.34%via NVD
CVE-2026-37236Critical· 9.8⚖ disputed
1mo ago

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-ww…

▾ MidnightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.43%via NVD
CVE-2026-55867Medium
1mo ago

Graylog is a free and open log management platform

Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog…

▾ Sunlitgraylog2 · org.graylog2:graylog2-serverEPSS 0.56%via NVD
CVE-2026-55228High· 8.1
1mo ago

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

▾ Twilightweblate · weblateEPSS 0.45%via OSV
CVE-2026-55516High· 7.7
1mo ago

Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update

Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update

▾ Twilightsnipe · snipe/snipe-itEPSS 0.38%via GHSA
CVE-2026-55065High· 8.1
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only a…

▾ Twilightapi · code.vikunja.io/apiEPSS 0.50%via NVD
CVE-2026-55066High· 7.1
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket…

▾ Twilightapi · code.vikunja.io/apiEPSS 0.37%via NVD
CVE-2026-55067Medium· 5.0
1mo ago

Vikunja is an open-source self-hosted task management platform

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket} allows the request body project_view_id value to be mass assigned by Bucket.Update in pkg/model…

▾ Sunlitapi · code.vikunja.io/apiEPSS 0.34%via NVD
CVE-2026-54746Medium· 6.4
1mo ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not verify that a request's worker ID belongs to the tenant identified by the…

▾ Sunlithatchet-dev · github.com/hatchet-dev/hatchetEPSS 0.37%via NVD
CVE-2026-77368High· 7.6
1mo ago

SeaweedFS is a distributed storage system for files and blobs

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another te…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-69129None
1mo ago

KubePi is a Kubernetes multi-cluster management panel

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not consistently validate per-cluster access, allowing an authenticated user with cluster management permissions to oper…

▾ SunlitEPSS 0.41%via NVD
CWE-639 vulnerabilities (CVEs) — page 12 · VulnSea