VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

670 CVEsRSS

CVE-2026-11900Medium· 4.3
2mo ago

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 2.8.16 via the 'data' attribute of the [adinserter] shortcode

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 2.8.16 via the 'data' attribute of the [adinserter] shortcode. This is due to the replace_a…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-9180Medium· 5.3
2mo ago

The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4

The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This is due to the `POST /motopress/appointment/v1/bookings` REST endpo…

▾ SunlitEPSS 0.56%via NVD
GHSA-j5mc-p8qg-39j7Low
2mo ago

Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation

Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation

▾ Sunlitkimai · kimai/kimaivia GHSA
CVE-2026-50194High· 8.2
2mo ago

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

Steeltoe vulnerable to management-port isolation bypass via spoofed Host header

▾ TwilightSteeltoe · Steeltoe.Management.EndpointEPSS 0.41%via GHSA
CVE-2026-50283Medium
2mo ago

Craft CMS: Unauthorized Deletion of Source Assets During File Replacement

Craft CMS: Unauthorized Deletion of Source Assets During File Replacement

▾ Sunlitcraftcms · craftcms/cmsEPSS 0.36%via GHSA
GHSA-f9ff-5x35-7gfwHigh
2mo ago

Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)

Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)

▾ Twilightgrackle-ai · @grackle-ai/mcpvia GHSA
GHSA-6vg3-hgrw-p5gfMedium· 5.4
2mo ago

SurrealDB has an Authorization Bypass via Composite Record-id Paths

SurrealDB has an Authorization Bypass via Composite Record-id Paths

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-47198High· 8.5
2mo ago

Paymenter has URL parameter injection that bypasses paid plan limits at checkout

Paymenter has URL parameter injection that bypasses paid plan limits at checkout

▾ Twilightpaymenter · paymenter/paymenterEPSS 0.40%via GHSA
CVE-2026-13534Medium· 5.0
3mo ago

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument s…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13512Medium· 6.3
3mo ago

A vulnerability was identified in Databend up to 1.2.881 on HTTP

A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handl…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-12411High· 8.4
3mo ago

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when securi…

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when securi…

▾ Twilightcanonical · lxdEPSS 0.29%via NVD
CVE-2026-52782Critical· 9.9PoC
3mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" l…

▾ AbyssalEPSS 0.45%via NVD
CVE-2026-49355Medium· 4.3
3mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/agenda_items/:agenda_item_id` discloses private work package data from a linked work package that belongs to a private/…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-44732Medium· 4.3
3mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a document update endpoint used to modify existing documents. The target document is loaded with visibility checks and the…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-44731Medium· 4.3
3mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's meetings filter feature leaks whether a given user ID corresponds to a valid account and discloses the user's full name,…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-49258High· 8.8
3mo ago

Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)

Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.48%via GHSA
GHSA-7vfx-4246-jcfhHigh
3mo ago

SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings

SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings

▾ Twilightsolidinvoice · solidinvoice/solidinvoicevia GHSA
GHSA-q6xx-5vr8-p898Critical· 9.9
3mo ago

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check

▾ Midnightnezhahq · github.com/nezhahq/nezhavia GHSA
CVE-2026-49339High· 7.1
3mo ago

gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists

gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists

▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.39%via GHSA
CVE-2026-49338High· 7.1
3mo ago

Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)

Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)

▾ Twilightgonic · go.senan.xyz/gonicEPSS 0.29%via GHSA
GHSA-vjr9-f93j-mjr7High· 8.1
3mo ago

Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

Duplicate Advisory: OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

▾ Twilightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-52812High
3mo ago

Gogs: LFS dedupe path leaks private repo content across tenants

Gogs: LFS dedupe path leaks private repo content across tenants

▾ Twilightgogs · gogs.io/gogsEPSS 0.24%via GHSA
CVE-2026-54518Medium· 6.5
3mo ago

jackson-databind: jackson-databind: Information disclosure and data manipulation via view-based access control bypass (CVE-2026-54518)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security view restrictions by sending specially crafted JSON (JavaScript Object Notation) data. The UnwrappedPropertyHandler component, which proce…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.35%via CSAF
CVE-2026-6062Medium· 6.4
3mo ago

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.24%via OSV
CVE-2026-52799High· 7.5
3mo ago

Gogs Missing Authorization in Attachment Download

Gogs Missing Authorization in Attachment Download

▾ Twilightgogs · gogs.io/gogsEPSS 0.42%via GHSA
CVE-2026-56120Critical· 9.6
3mo ago

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)

▾ Midnightopenremote · io.openremote:openremote-managervia GHSA
CVE-2026-53726Medium
3mo ago

parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL

parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL

▾ Sunlitparse-server · parse-serverEPSS 0.48%via GHSA
CVE-2026-55255Critical· 9.9CISA KEVPoC
3mo ago

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow

▾ Hadallangflow · langflowEPSS 0.89%via GHSA
GHSA-x26h-xmv8-gxf7High
3mo ago

stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)

stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)

▾ Twilightstigmem-node · stigmem-nodevia GHSA
GHSA-xhv3-q4xx-349rHigh
3mo ago

stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)

stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)

▾ Twilightstigmem-node · stigmem-nodevia GHSA
CWE-639 vulnerabilities (CVEs) — page 20 · VulnSea