VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

668 CVEsRSS

CVE-2026-48494None
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blo…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-47704None
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockI…

▾ SunlitEPSS 0.56%via NVD
CVE-2026-73068Medium· 5.9
1mo ago

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes op…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-72774Medium· 6.5
1mo ago

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the crede…

▾ Sunlitn8n · n8nEPSS 0.44%via NVD
CVE-2026-58650High· 7.8
1mo ago

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

▾ Twilightmicrosoft · visual_studio_codeEPSS 0.32%via NVD
CVE-2026-19579Medium· 5.4
1mo ago

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments …

▾ Sunlitsnipeitapp · snipe-itEPSS 0.34%via NVD
CVE-2026-69114Medium· 6.5PoC
1mo ago

Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to the requested channel

Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to the requested channel. Authenticated users with MAN…

▾ TwilightSpacebar Server · Spacebar ServerEPSS 0.39%via NVD
CVE-2026-68870Medium· 5.3
1mo ago

The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed

The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mod…

▾ SunlitApache Software Foundation · apache-airflow-providers-microsoft-azureEPSS 0.36%via NVD
CVE-2026-18620High· 7.1
1mo ago

A flaw was found in Data Science Pipelines

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRu…

▾ TwilightRed Hat · rhoai/odh-ml-pipelines-api-server-v2-rhel9EPSS 0.48%via NVD
CVE-2026-72876Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s server…

▾ MidnightEPSS 0.71%via NVD
CVE-2026-72863Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via valida…

▾ MidnightEPSS 0.55%via NVD
CVE-2026-72737Critical· 9.6
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accept a client-controlled destinationId an…

▾ MidnightEPSS 0.35%via NVD
CVE-2026-72734High· 8.4
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/routers/server.ts accepts a caller-controlled serverId and calls haveActiveServices, fin…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-72724Medium· 4.3
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/chat/onebox_handler.rb resolves Chat::Thread by route thread_id independently of the route channel_id before checking …

▾ SunlitEPSS 0.63%via NVD
CVE-2026-72564Critical· 9.6
1mo ago

An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.

An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.

▾ MidnightEPSS 0.44%via NVD
CVE-2026-68871Medium· 6.5
1mo ago

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with thi…

▾ Sunlitapache · apache-airflow-providers-apache-yandexEPSS 0.60%via NVD
CVE-2026-68872Medium· 6.5
1mo ago

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deploymen…

▾ Sunlitapache · apache-airflow-providers-amazonEPSS 0.60%via NVD
CVE-2026-70561Medium· 6.5PoC
1mo ago

TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the a…

TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the a…

▾ TwilightTestLinkOpenSourceTRMS · TestLinkEPSS 0.37%via NVD
CVE-2026-66058None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.

▾ SunlitEPSS 0.38%via NVD
CVE-2026-48169High· 8.8
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key…

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.44%via NVD
CVE-2026-70557Medium· 6.5
1mo ago

diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those values for all rows, with no field or entity allowlist

diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those values for all rows, with no field or entity allowlist. The only guard, relatedDataSecur…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-67622Critical· 9.9
1mo ago

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary crede…

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary crede…

▾ Midnightflowiseai · flowiseEPSS 0.48%via NVD
CVE-2026-66692Medium· 4.3
1mo ago

Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.

Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.

▾ SunlitEPSS 0.27%via NVD
CVE-2026-64662Medium· 6.5
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and cust…

▾ Sunlitstatamic · statamic/cmsEPSS 0.41%via NVD
CVE-2026-45414High· 8.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be …

▾ Twilightdecidim · decidimEPSS 0.45%via NVD
CVE-2026-55739High· 8.3
1mo ago

Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->company_id)

Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check enti…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-59733High· 8.8
1mo ago

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

▾ Twilightrclone · github.com/rclone/rcloneEPSS 0.55%via GHSA
CVE-2026-59817Medium· 5.3
1mo ago

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

Ghost: Paid gift memberships obtainable at minimal cost via the donations feature

▾ Sunlitghost · ghostEPSS 0.40%via GHSA
CVE-2026-70488Medium· 4.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids su…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-70476High· 8.2
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterp…

▾ Twilightflowiseai · flowiseEPSS 0.52%via NVD
CWE-639 vulnerabilities (CVEs) — page 16 · VulnSea