VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

668 CVEsRSS

GHSA-86cx-wwf4-phq4Medium· 6.5
2mo ago

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenList/v4via GHSA
GHSA-c8vc-7pv3-g98pHigh
2mo ago

Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)

Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-rjg6-39jm-rgg4Critical· 9.9
2mo ago

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

▾ Midnightbetter-auth · @better-auth/scimvia GHSA
GHSA-h3rm-78g3-j7cpHigh· 7.1
2mo ago

@better-auth/stripe: cross-organization billing tampering in organization subscription actions

@better-auth/stripe: cross-organization billing tampering in organization subscription actions

▾ Twilightbetter-auth · @better-auth/stripevia GHSA
CVE-2026-15630Critical· 9.9PoC
2mo ago

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

▾ AbyssalCasdoor · CasdoorEPSS 0.34%via NVD
CVE-2026-65013High· 8.8PoC
2mo ago

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API…

▾ Midnightonlook · repoEPSS 0.52%via NVD
CVE-2026-59259Medium
2mo ago

n8n: External Secrets Permission Bypass via Expression Parser Mismatch

n8n: External Secrets Permission Bypass via Expression Parser Mismatch

▾ Sunlitn8n · n8nEPSS 0.44%via GHSA
CVE-2026-59254Medium
2mo ago

n8n: External Secrets Accessible via Workflow Expressions Outside Credentials

n8n: External Secrets Accessible via Workflow Expressions Outside Credentials

▾ Sunlitn8n · n8nEPSS 0.36%via GHSA
CVE-2026-59253Medium
2mo ago

n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects

n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects

▾ Sunlitn8n · n8nEPSS 0.28%via GHSA
GHSA-mwq7-vcmc-cm4qHigh
2mo ago

Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner

Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner

▾ Twilightn8n · n8nvia GHSA
CVE-2026-65016High
2mo ago

n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner

n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner

▾ Twilightn8n · n8nEPSS 0.45%via GHSA
CVE-2026-65316Medium· 6.5
2mo ago

xxl-job Cross-Job-Group Log Disclosure via Missing Authorization Check in /joblog/logDetailCat

XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to…

▾ Sunlitxuxueli · xxl-jobEPSS 0.51%via CVEORG
CVE-2026-58435Medium· 5.4
2mo ago

Gitea LFS Deploy-Key Privilege Escalation

Gitea LFS Deploy-Key Privilege Escalation

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.29%via GHSA
CVE-2026-58432Medium· 5.9
2mo ago

Gitea: draft release attachment disclosure via missing web authorization

Gitea: draft release attachment disclosure via missing web authorization

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.43%via GHSA
CVE-2026-57886Medium· 5.9
2mo ago

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content

Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.31%via GHSA
CVE-2026-58445Low· 2.7
2mo ago

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.37%via GHSA
CVE-2026-13381High· 8.1
2mo ago

VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint

VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and dele…

▾ Twilightvsee · clinicEPSS 0.37%via NVD
CVE-2026-61836High· 8.6
2mo ago

Directus: Authorization-dependent response served from unsegmented cache key

Directus: Authorization-dependent response served from unsegmented cache key

▾ Twilightdirectus · directusEPSS 0.47%via GHSA
CVE-2026-16217Medium· 6.3
2mo ago

A security vulnerability has been detected in guohongze adminset up to 0.61

A security vulnerability has been detected in guohongze adminset up to 0.61. Affected by this vulnerability is an unknown functionality of the file delivery/deli.py of the component Delivery Deployment Endpoint. The manipulation of the a…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-16214Medium· 6.3
2mo ago

A vulnerability was identified in geex-arts django-jet up to 1.0.8

A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the component Dashboard Module. Such manipulation leads to authorization bypass. The attack can be…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-16075Medium· 4.3
2mo ago

A flaw has been found in AstrBotDevs AstrBot up to 4.25.5

A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing Endpoint. This manipulati…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-15945Medium· 4.3
2mo ago

A flaw was found in the group search functionality of the Keycloak server's administrative API

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they…

▾ Sunlitredhat · build_of_keycloakEPSS 0.35%via NVD
CVE-2026-53536None
2mo ago

Activepieces is an open source AI workflow automation platform

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared signing secret but did not check the token's audience, and combined…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-52869High· 7.1
2mo ago

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal

▾ Twilightmcp · mcpEPSS 0.53%via OSV
CVE-2026-52882Medium
2mo ago

MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters

MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters

▾ Sunlitmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-15637High· 7.5
2mo ago

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credenti…

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credenti…

▾ Twilightdevolutions · devolutions_serverEPSS 0.25%via NVD
CVE-2026-15058Low· 3.1
2mo ago

Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.

Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.

▾ Sunlitdevolutions · devolutions_serverEPSS 0.21%via NVD
CVE-2026-50141High
2mo ago

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

▾ Twilightwoodpecker · go.woodpecker-ci.org/woodpecker/v3EPSS 0.43%via GHSA
CVE-2026-54052Critical· 9.9
2mo ago

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

▾ Midnightn8n-mcp · n8n-mcpEPSS 0.39%via GHSA
CVE-2025-32781Medium· 6.5
2mo ago

Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center

Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center

▾ Sunlitctrip · com.ctrip.framework.apollo:apolloEPSS 0.41%via GHSA
CWE-639 vulnerabilities (CVEs) — page 18 · VulnSea