VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

668 CVEsRSS

CVE-2026-63669Medium· 6.5
1mo ago

ApostropheCMS is an open-source Node.js content management system

ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldParent archive condition disables the chec…

▾ Sunlitapostrophe · apostropheEPSS 0.31%via NVD
CVE-2026-69146Medium· 6.5
1mo ago

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any a…

▾ Sunlitmlflow · mlflowEPSS 0.39%via NVD
CVE-2026-13358Medium· 6.5
1mo ago

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to mi…

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to mi…

▾ SunlitEPSS 0.68%via NVD
CVE-2026-12905Medium· 4.3
1mo ago

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabin…

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabin…

▾ SunlitEPSS 0.39%via NVD
CVE-2025-10005Medium· 4.3
1mo ago

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.20 via the ppw_free_set_password AJAX action due to…

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.20 via the ppw_free_set_password AJAX action due to…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-16142Critical· 9.8
1mo ago

The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6

The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitr…

▾ MidnightEPSS 0.66%via NVD
CVE-2026-73039Medium· 5.4
1mo ago

streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status records

streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status records. Attackers can enumerate all users' watch progress, dele…

▾ Sunlitstreamaserver · streamaEPSS 0.30%via NVD
CVE-2026-73616Medium· 6.5
1mo ago

OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms

OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to rem…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-73656Critical· 9.9
1mo ago

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/a…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-73644Critical· 9.6
1mo ago

OpenDJ is an LDAPv3 compliant directory service

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privil…

▾ MidnightEPSS 0.41%via NVD
CVE-2026-72741High· 8.1
1mo ago

Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL path…

Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL path…

▾ TwilightEPSS 0.26%via NVD
CVE-2026-73657Medium· 4.2
1mo ago

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-73612High· 8.1
1mo ago

File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls

File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete de…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-72657Medium· 6.5
1mo ago

Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77)

Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variables (CAPEC-77). The authorization decision for artifact downloads relied on a client-sup…

▾ Sunlitelastic · fleet_serverEPSS 0.39%via NVD
CVE-2026-73841High· 8.8
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:vi…

▾ Twilightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.81%via NVD
CVE-2026-73298None
1mo ago

The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service

The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and…

▾ SunlitEPSS 0.97%via NVD
CVE-2026-47230Medium· 6.5
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same root-cause shape as the cross-folder move bug (`05-documents-cross-folder-move-idor.md`): …

▾ SunlitAdmidio · admidioEPSS 0.30%via NVD
CVE-2026-47227Medium· 6.5PoC
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …) corresponds to a module the actor administers. The follow-up "is this specific categor…

▾ TwilightAdmidio · admidioEPSS 0.33%via NVD
CVE-2026-47231High· 8.1
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking that the actor has `hasUploadRight()` on the URL parameter `folder_uuid`. The `move_save` h…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-47226Medium· 6.5
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can permanently delete files from folders where they have only view access. The authorizati…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-73303High· 8.2
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authen…

▾ TwilightEPSS 0.31%via NVD
CVE-2026-18750Medium· 5.3
1mo ago

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notific…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-18749Critical· 9.8
1mo ago

The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared

The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is…

▾ MidnightEPSS 0.51%via NVD
CVE-2026-18744Medium· 6.5
1mo ago

Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership of kwargs['member']

Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership of kwargs['member']. Bypasses share_status; leaks e…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-64927Medium· 6.4
1mo ago

A flaw was found in the multicloud-operators-channel component

A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.33%via NVD
CVE-2026-68076Medium· 5.4
1mo ago

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a …

▾ Sunlitapache · airflowEPSS 0.62%via NVD
CVE-2026-19130Medium· 5.8
1mo ago

A flaw was found in the provider-credential-controller component of multicluster-engine (MCE)

A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vul…

▾ SunlitRed Hat · multicluster-engine/provider-credential-controller-rhel9EPSS 0.40%via NVD
CVE-2026-69119High· 8.3
1mo ago

Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GE…

Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GE…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-69117Medium· 6.5
1mo ago

NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references by supplying crafted JSO…

NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references by supplying crafted JSO…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-48765Critical· 9.9
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOA…

▾ MidnightEPSS 0.46%via NVD
CWE-639 vulnerabilities (CVEs) — page 15 · VulnSea