VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

670 CVEsRSS

CVE-2026-54052Critical· 9.9
2mo ago

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments

▾ Midnightn8n-mcp · n8n-mcpEPSS 0.39%via GHSA
CVE-2025-32781Medium· 6.5
2mo ago

Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center

Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center

▾ Sunlitctrip · com.ctrip.framework.apollo:apolloEPSS 0.41%via GHSA
CVE-2026-9708Medium· 4.9
2mo ago

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to…

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-10103Medium· 4.3
2mo ago

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by loca…

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by loca…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-14165High· 7.5
2mo ago

An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization.

An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization.

▾ TwilightEPSS 0.42%via NVD
CVE-2026-15516Medium· 5.6
2mo ago

A vulnerability was detected in MacCMS Pro up to 2022.1000.3005

A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. …

▾ SunlitEPSS 0.44%via NVD
CVE-2026-10041Medium· 4.3
2mo ago

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled k…

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 via the wcfm_product_archive due to missing validation on a user controlled k…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-13116Medium· 4.3
2mo ago

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user …

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user …

▾ SunlitEPSS 0.39%via NVD
CVE-2026-55881None
2mo ago

OpenReplay is a self-hosted session replay suite

OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3 download URLs for a session's DOM-replay recording based solely on the session path parameter, while validateProject…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-55880High· 7.1
2mo ago

OpenReplay is a self-hosted session replay suite

OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the ownership predicate that their sibling read and edit functions use: notes.delete filtered only…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-55515Medium· 5.0
2mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and deletes CheckoutAcceptance::pending()->find($acceptanceId) by global ID without checking acc…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-6212High· 8.8
2mo ago

Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc

Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Privilege Abuse. This issue affects TeraMIS: from V03.26.01.14 through 30.04.2026.

▾ TwilightEPSS 0.44%via NVD
CVE-2026-61460High· 8.8
2mo ago

Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or …

Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or …

▾ TwilightEPSS 0.51%via NVD
CVE-2026-55478Medium· 5.4
2mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user …

▾ Sunlitsnipeitapp · snipe-itEPSS 0.29%via NVD
CVE-2026-49858Medium· 5.9
2mo ago

API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate

API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate

▾ Sunlitapi-platform · api-platform/coreEPSS 0.32%via GHSA
CVE-2026-15191Medium· 6.3
2mo ago

A flaw has been found in mettle sendportal up to 3.0.1

A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation Endpoint. Executing a…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-59215Low· 3.1
2mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to the channel in the URL, allowing an authenticated user to reference…

▾ Sunlitopenwebui · open_webuiEPSS 0.32%via NVD
CVE-2026-59216High· 7.7
2mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the…

▾ Twilightopenwebui · open_webuiEPSS 0.45%via NVD
CVE-2026-35210High· 7.1
2mo ago

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0, an authorization bypass vulnerability in OpenCTI allows any authenticated user with KNOWLEDGE_KNUPDATE permission t…

▾ Twilightciteum · openctiEPSS 0.35%via NVD
CVE-2026-49296Medium· 6.5
2mo ago

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the en…

▾ Sunlitapache · airflowEPSS 0.60%via NVD
GHSA-j8v8-g9cx-5qf4High· 8.3
2mo ago

@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers

@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers

▾ Twilightbetter-auth · @better-auth/scimvia GHSA
CVE-2026-27823Critical
2mo ago

EGroupware has a Remote Code Execution Vulnerability

EGroupware has a Remote Code Execution Vulnerability

▾ Midnightegroupware · egroupware/egroupwareEPSS 0.97%via GHSA
CVE-2026-59712High· 8.1
2mo ago

Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes, TOTP secrets, and session tokens

Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes, TOTP secrets, and session tokens. Attackers can exploit…

▾ TwilightLeantime · LeantimeEPSS 0.45%via NVD
CVE-2026-54641High· 7.7
2mo ago

OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl

OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl

▾ Twilightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-55429High· 8.7
2mo ago

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.51%via GHSA
CVE-2026-28740High· 7.1
2mo ago

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.

▾ TwilightEPSS 0.32%via NVD
CVE-2026-27657None
2mo ago

Gitea versions before 1.25.5 allow a user to change another user's primary email address.

Gitea versions before 1.25.5 allow a user to change another user's primary email address.

▾ SunlitEPSS 0.45%via NVD
CVE-2026-25782None
2mo ago

Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

Gitea versions before 1.25.5 look up tracked-time entries by time ID without scoping the lookup to the issue in the request URL, allowing deletion attempts to target entries from another issue.

▾ SunlitEPSS 0.39%via NVD
CVE-2026-14608Medium· 4.3
2mo ago

A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0

A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler.…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-59234None
2mo ago

Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3 …

Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3 …

▾ SunlitEPSS 0.64%via NVD
CWE-639 vulnerabilities (CVEs) — page 19 · VulnSea