VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

668 CVEsRSS

CVE-2026-81031High· 7.2
1mo ago

IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request

IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves the…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-79654Medium· 4.3
1mo ago

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization m…

▾ SunlitRed Hat · rubygem-katelloEPSS 0.34%via NVD
CVE-2026-54590Medium· 5.9
1mo ago

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakl…

asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

▾ Sunlitasyncssh · asyncsshEPSS 0.39%via OSV
CVE-2026-54553Medium· 5.4
1mo ago

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

▾ Sunlitstarlette-admin · starlette-adminEPSS 0.45%via OSV
CVE-2026-54256Medium· 5.4
1mo ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget trusted an attacker-controlled file_id POST parameter when resolving the attachment …

▾ Sunlitwinter · winter/wn-backend-moduleEPSS 0.24%via NVD
CVE-2026-35445High
1mo ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated b…

▾ Twilightwinter · winter/wn-backend-moduleEPSS 0.44%via NVD
CVE-2026-80049High· 8.8
1mo ago

Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies

Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and Authent…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-56093Medium· 6.3
1mo ago

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retriev…

▾ SunlitTYPO3 · apache-solr-for-typo3/solrEPSS 0.31%via NVD
CVE-2026-77127Medium· 6.0
1mo ago

Information Disclosure in extension "Modules" (modules)

The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and…

▾ SunlitTYPO3 · codingms/modulesEPSS 0.35%via CVEORG
CVE-2026-62861None
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another workspace's public custom domain and make typebots on that domain unavailable. The custom-domain delete handler in handle…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-77998Critical· 10.0
1mo ago

Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Ap…

Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Ap…

▾ Midnightminiorange.com · SAML SSO Free for Joomla extension for JoomlaEPSS 0.60%via NVD
CVE-2026-55604High· 8.6
1mo ago

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

▾ Twilightarikusi · @arikusi/deepseek-mcp-serverEPSS 0.37%via GHSA
CVE-2026-76073High· 8.8
1mo ago

Label Studio does not scope the annotation detail endpoint to the requesting user's organization

Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the defau…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-71507Medium· 6.5
1mo ago

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank a…

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank a…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-71505High· 7.1
1mo ago

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal passw…

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal passw…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-77995Critical· 10.0
1mo ago

Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes…

Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes…

▾ Midnightminiorange.com · miniOrange OAuth Client (free) extension for JoomlaEPSS 0.41%via NVD
CVE-2026-77769Medium· 6.5
1mo ago

The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId)

The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for …

▾ SunlitEPSS 0.31%via NVD
CVE-2026-77768Medium· 6.5
1mo ago

The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly

The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input ca…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-77776Critical· 9.1
1mo ago

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing …

▾ MidnightEPSS 0.61%via NVD
CVE-2026-62283Critical· 9.9
1mo ago

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_strea…

▾ Midnightnezhahq · github.com/nezhahq/nezhaEPSS 0.55%via NVD
CVE-2026-62945Medium· 4.3
1mo ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using findForeignLinkTarget() to verify that the ref…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-55489Medium· 4.9
1mo ago

BigBlueButton is an open-source virtual classroom

BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. akka-bbb-apps/src/main/scala/org…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-76634Medium· 6.5
1mo ago

WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request ext…

WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request ext…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-69558High· 8.6
1mo ago

Microsoft Partner Center Information Disclosure Vulnerability

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Microsoft Partner CenterEPSS 0.97%via CVEORG
CVE-2026-54622Medium· 6.5
1mo ago

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

▾ Sunlitdjango-cms · django-cmsEPSS 0.41%via OSV
CVE-2026-63003Medium· 6.5
1mo ago

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on the source page. In cms/admin/forms.py, DuplicatePa…

▾ Sunlitdjango-cms · django-cmsEPSS 0.41%via NVD
CVE-2026-61663Medium· 4.3
1mo ago

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

▾ Sunlitdjango-cms · django-cmsEPSS 0.34%via OSV
GHSA-mpmw-f6h6-3g26Medium· 4.3
1mo ago

Winter: My Account preview exposes another backend user's profile by record ID

Winter: My Account preview exposes another backend user's profile by record ID

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
CVE-2026-76216High· 7.5
1mo ago

Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards

Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards. Attackers with a link-share …

▾ TwilightEPSS 0.36%via NVD
CVE-2026-53546Critical· 9.6PoC
1mo ago

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/backend/ssh/host-resolver.ts resolves th…

▾ AbyssalTermix-SSH · TermixEPSS 0.46%via NVD
CWE-639 vulnerabilities (CVEs) — page 13 · VulnSea