VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

668 CVEsRSS

CVE-2026-68559Medium· 6.5
1mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/exportExcel route in models/exportExcel.js called the asynchronous exporterExcel.canExport(user) authorization guard from models/server/Exporte…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-53548Critical· 9.6
1mo ago

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated use…

▾ MidnightEPSS 0.46%via NVD
CVE-2026-62666High· 8.8
1mo ago

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, Grav API plugin UsersController::createApiKey(), generate2fa(), and disable2fa() omit the accessGrantsSuper() target…

▾ TwilightEPSS 0.64%via NVD
CVE-2026-51367High· 7.5
1mo ago

An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter

An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter

▾ TwilightEPSS 0.60%via NVD
CVE-2026-76647High· 8.8
1mo ago

Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php

Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php. The dispatcher does not enforce authorization before invoking service-layer …

▾ TwilightEPSS 0.51%via NVD
CVE-2026-76237High
1mo ago

stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints

stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant, the list/count qu…

▾ Twilightstigmem-node · stigmem-nodeEPSS 0.36%via NVD
CVE-2026-76236High
1mo ago

stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism

stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant,…

▾ Twilightstigmem-node · stigmem-nodeEPSS 0.36%via NVD
CVE-2026-59992Medium· 5.4
1mo ago

Tina is a headless content management system

Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled obj…

▾ Sunlitnext-tinacms-s3 · next-tinacms-s3EPSS 0.38%via NVD
CVE-2026-55694High
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-…

▾ Twilightsnipe · snipe/snipe-itEPSS 0.41%via NVD
CVE-2026-55482Medium· 6.3
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing asse…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.33%via NVD
CVE-2026-50167None
1mo ago

Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage

Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.4, Kurrier API endpoints for listing and retrieving webhook and identity resources did not enforce ownership checks for authenticated API…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-69189High· 7.6
1mo ago

Hoppscotch is an open source API development ecosystem

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose an…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-19869None
1mo ago

@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-level @authentication rule is also present on the same operation type

@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-level @authentication rule is also present on the same operation type. When both a type-le…

▾ SunlitEPSS 0.49%via NVD
CVE-2026-61574High· 8.8
1mo ago

authentik is an open-source identity provider

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and …

▾ TwilightEPSS 0.62%via NVD
CVE-2026-49228High· 8.8
1mo ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product operations allow a low-privileged Vendor to access products owned by another Vendor. The admi…

▾ TwilightEPSS 0.55%via NVD
CVE-2026-49227High· 7.6
1mo ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend comment operations allow a low-privileged Author to manage comments under another Author's posts. The…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-49226High· 8.3
1mo ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post operations allow a low-privileged Author to access posts owned by another Author. The admin/cont…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-49225High· 8.3
1mo ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revision operations allow a low-privileged Vendor to access revisions for products owned by a…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-49224High· 8.3
1mo ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post revision operations allow a low-privileged Author to access revisions for posts owned by another…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-49223High· 7.6
1mo ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product review operations allow a low-privileged Vendor to manage reviews under another Vendor's prod…

▾ TwilightEPSS 0.42%via NVD
CVE-2026-49222High· 7.6
1mo ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product question operations allow a low-privileged Vendor to manage questions under another Vendor's …

▾ TwilightEPSS 0.42%via NVD
CVE-2026-49221High· 8.8
1mo ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset operations allow a low-privileged Vendor to access digital assets linked to another Ven…

▾ TwilightEPSS 0.55%via NVD
CVE-2026-45120Medium· 5.4
1mo ago

MyBB is free and open source forum software

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users with viewing and moderation permissions to access and moderate private events. The privat…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-71308High· 8.1
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects without a Certific…

▾ Twilightlemur · lemurEPSS 0.32%via NVD
CVE-2026-71417High· 7.3
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using another certificate body, authority_id, serial, or external_id without requiring permiss…

▾ Twilightlemur · lemurEPSS 0.10%via NVD
CVE-2026-69160Medium· 6.5
1mo ago

OpenList a file list program that supports multiple storage

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use strings.HasPrefix(requested_path, user.BasePath) without enforcing a directory separator b…

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenList/v4EPSS 0.40%via NVD
CVE-2026-55166Critical· 9.9
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend req…

▾ Midnightlemur · lemurEPSS 0.29%via NVD
CVE-2026-75105High· 7.5
1mo ago

phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for

phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId pa…

▾ Twilightphpipam · phpipamEPSS 0.48%via NVD
CVE-2026-75103High· 8.8PoC
1mo ago

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and c…

▾ Midnightcrawlab-team · crawlabEPSS 0.43%via NVD
CVE-2026-63178Medium· 6.5
1mo ago

Onyx is an open-source AI platform

Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/user-group/{user_group_id}/add-users endpoints in ee/onyx/server/user_group/api.py call u…

▾ SunlitEPSS 0.52%via NVD
CWE-639 vulnerabilities (CVEs) — page 14 · VulnSea