VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

668 CVEsRSS

CVE-2026-69258Critical· 9.1
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into intern…

▾ Midnightflowiseai · flowiseEPSS 0.67%via NVD
GHSA-2364-jh4q-m9vmMedium
1mo ago

Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint

▾ Sunlitflowise · flowisevia GHSA
CVE-2026-69250High· 7.5
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a s…

▾ Twilightflowiseai · flowiseEPSS 0.57%via NVD
CVE-2026-69094Medium· 4.3
1mo ago

Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations

Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs a…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-46712None
1mo ago

Misskey is an open source, federated social media platform

Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper permission checks allows access to certain data points from the Direct Message…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-68582Medium· 6.5
1mo ago

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks)

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view f…

▾ SunlitEPSS 0.36%via NVD
CVE-2025-71400High· 7.1
1mo ago

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can su…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-67342Critical· 9.8
1mo ago

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify d…

▾ MidnightEPSS 0.54%via NVD
CVE-2026-67331High· 8.3
1mo ago

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-67329High· 7.1
1mo ago

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query…

▾ TwilightEPSS 0.31%via NVD
CVE-2025-14073Medium· 5.3
1mo ago

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_orde…

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_orde…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-65981High· 7.1
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the or…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-16105Medium· 4.9
1mo ago

A flaw was found in the RoleContainerResource component of Keycloak

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a de…

▾ Sunlitredhat · build_of_keycloakEPSS 0.42%via NVD
CVE-2026-17349Critical· 9.6
1mo ago

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including u…

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including u…

▾ MidnightEPSS 0.40%via NVD
CVE-2026-17567Medium· 5.3
1mo ago

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter…

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.2.8 via the 'transaction' parameter…

▾ SunlitEPSS 0.63%via NVD
CVE-2026-45330Medium· 4.9
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier wi…

▾ Sunlitdecidim-verifications · decidim-verificationsEPSS 0.46%via NVD
CVE-2026-10700Medium· 6.5
1mo ago

IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce a…

IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce a…

▾ SunlitEPSS 0.54%via NVD
CVE-2026-12945High· 7.1
1mo ago

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.

▾ TwilightEPSS 0.36%via NVD
CVE-2026-68500High· 7.5
1mo ago

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId paramete…

▾ Twilightsylius · sylius/mollie-pluginEPSS 0.68%via NVD
CVE-2026-68501Medium· 6.5
1mo ago

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCode…

▾ Sunlitsylius · sylius/mollie-pluginEPSS 0.60%via NVD
CVE-2026-52839Low· 3.3
2mo ago

Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass

Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass

▾ Sunlitalextselegidis · alextselegidis/easyappointmentsEPSS 0.23%via GHSA
CVE-2026-52837Medium
2mo ago

Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page

▾ Sunlitalextselegidis · alextselegidis/easyappointmentsEPSS 0.56%via GHSA
CVE-2026-52841Low· 3.1
2mo ago

Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync

Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync

▾ Sunlitalextselegidis · alextselegidis/easyappointmentsEPSS 0.21%via GHSA
CVE-2026-66412Medium· 6.5PoC
2mo ago

Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPC

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying arbitrary integer milestone IDs to the tickets.getMileston…

▾ TwilightLeantime · LeantimeEPSS 0.41%via CVEORG
CVE-2026-17527High· 7.7
2mo ago

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone a…

▾ TwilightRed Hat · container-native-virtualization/virt-cdi-operator-rhel9EPSS 0.57%via NVD
CVE-2026-66013None
2mo ago

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwri…

▾ SunlitEPSS 0.68%via NVD
CVE-2026-17059Medium· 6.5
2mo ago

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has…

▾ Sunlitredhat · build_of_keycloakEPSS 0.41%via NVD
GHSA-p279-2cqp-84jgCritical· 9.6
2mo ago

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check

▾ Midnightopenidentityplatform · org.openidentityplatform.opendj:opendj-server-legacyvia GHSA
GHSA-rm67-g9ch-vxffHigh· 8.1
2mo ago

Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own

Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own

▾ Twilightpoweradmin · poweradmin/poweradminvia GHSA
GHSA-p6ph-3jx2-3337Medium· 4.3
2mo ago

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenList/v4via GHSA
CWE-639 vulnerabilities (CVEs) — page 17 · VulnSea