VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

670 CVEsRSS

CVE-2025-13822Medium· 5.3
5mo ago

MCPHub in versions below 0.11.0 is vulnerable to authentication bypass

MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their pri…

▾ Sunlitmcphubx · mcphubEPSS 0.35%via NVD
CVE-2026-4398Medium· 5.4
5mo ago

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from n…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from n…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-2104Medium· 4.3
5mo ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to other use…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to access confidential issues assigned to other use…

▾ Sunlitgitlab · gitlabEPSS 0.31%via NVD
CVE-2026-4654Medium· 5.3
5mo ago

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing …

▾ SunlitEPSS 0.44%via NVD
CVE-2026-5875Medium· 4.3
5mo ago

Policy bypass in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page

Policy bypass in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-32589High· 7.4
5mo ago

A flaw was found in Red Hat Quay's container image upload process

A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they…

▾ Twilightredhat · mirror_registry_for_red_hat_openshiftEPSS 0.43%via NVD
CVE-2026-34972Medium· 4.2
5mo ago

github.com/openfga/openfga: OpenFGA: Improper policy enforcement via specific BatchCheck calls (CVE-2026-34972)

A flaw was found in OpenFGA, a high-performance authorization engine. Under specific conditions, a user making BatchCheck calls with multiple checks for the same object, relation, and user combination can trigger improper policy enforcemen…

▾ SunlitRed Hat · Multicluster Global HubEPSS 0.27%via CSAF
CVE-2026-4896High· 8.1
5mo ago

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX action…

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX action…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-25197Critical· 9.1PoC
5mo ago

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

▾ Abyssalmygardyn · cloud_apiEPSS 0.29%via NVD
CVE-2026-3139Medium· 4.3
6mo ago

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value…

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-32976Medium· 6.5
6mo ago

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions

OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected sibling-account configuration despite configWrites restrictions. Attackers with authorized access on one account can e…

▾ Sunlitopenclaw · openclawEPSS 0.33%via NVD
CVE-2026-2366Low· 3.1
6mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated user, even those without administrative privileges, to enumerate the organization memberships of other users. This inf…

▾ Sunlitredhat · build_of_keycloakEPSS 0.27%via NVD
CVE-2025-69752Medium· 4.3
7mo ago

An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.

An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.

▾ SunlitEPSS 0.17%via NVD
CVE-2026-21721High· 8.1PoC
8mo ago

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on ot…

▾ Midnightgrafana · grafanaEPSS 0.73%via NVD
CVE-2025-14459High· 8.5
8mo ago

A flaw was found in KubeVirt Containerized Data Importer (CDI)

A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC sou…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-20912Critical· 9.1
8mo ago

Gitea does not properly validate repository ownership when linking attachments to releases

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to…

▾ Midnightgitea · giteaEPSS 0.46%via NVD
CVE-2026-20897Critical· 9.1
8mo ago

Gitea does not properly validate repository ownership when deleting Git LFS locks

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.

▾ Midnightgitea · giteaEPSS 0.46%via NVD
CVE-2025-49352Medium· 4.3
9mo ago

Authorization Bypass Through User-Controlled Key vulnerability in YoOhw Studio Order Cancellation & Returns for WooCommerce wc-order-cancellation-return allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

Authorization Bypass Through User-Controlled Key vulnerability in YoOhw Studio Order Cancellation & Returns for WooCommerce wc-order-cancellation-return allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a…

▾ SunlitEPSS 0.24%via NVD
CVE-2025-34438High· 8.1
9mo ago

AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video

AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video. The endpoint verifies upload capability but fails to enforce own…

▾ Twilightwwbn · avideoEPSS 0.28%via NVD
CVE-2025-41358None
9mo ago

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive

Direct Object Reference Vulnerability (IDOR) in i2A's CronosWeb, in versions prior to 25.00.00.12, inclusive. This vulnerability could allow an authenticated attacker to access other users' documents by manipulating the ‘documentCode’ pa…

▾ SunlitEPSS 0.34%via NVD
CVE-2025-66551Medium· 6.3
9mo ago

Nextcloud Tables allows you to create your own tables with individual columns

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 …

▾ Sunlitnextcloud · tablesEPSS 0.25%via NVD
CVE-2025-12997Low· 2.2
9mo ago

Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive…

Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device and user information to submit web requests to an API endpoint that would expose sensitive…

▾ Sunlitmedtronic · carelink_networkEPSS 0.18%via NVD
CVE-2025-65097Medium· 6.5
9mo ago

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, an Authenticated User can delete collections belonging to other users by dire…

▾ Sunlitromm.app · rommEPSS 0.21%via NVD
CVE-2025-65096Medium· 4.3
9mo ago

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. Prior to 4.4.1 and 4.4.1-beta.2, users can read private collections / smart collections belonging to other use…

▾ Sunlitromm.app · rommEPSS 0.19%via NVD
CVE-2025-66306Medium· 4.3
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts…

▾ Sunlitgetgrav · gravEPSS 0.29%via NVD
CVE-2025-52670Medium· 6.5
10mo ago

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.32%via NVD
CVE-2025-60511Medium· 4.3
11mo ago

Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in /blocks/openai_chat/api/completion.php

Moodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to insufficient validation of the blockId parameter in /blocks/openai_chat/api/completion.php. An authenticated …

▾ SunlitEPSS 0.22%via NVD
CVE-2025-9902High· 7.5
11mo ago

Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export Industry and Trade Co

Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export Industry and Trade Co. Ltd. QRMenu allows Privilege Abuse. This issue affects QRMenu: from 1.05.12 before Version dated 05.09.2025.

▾ TwilightEPSS 0.33%via NVD
CVE-2025-8463Medium· 5.3
1y ago

Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forceful Browsing. This issue affects SecHard: before 3.6.2-20250805.

Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forceful Browsing. This issue affects SecHard: before 3.6.2-20250805.

▾ SunlitEPSS 0.26%via NVD
CVE-2025-7718High· 8.8
1y ago

The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.5.4

The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.5.4. This is due to the plugin not properly validating a…

▾ TwilightEPSS 0.32%via NVD
CWE-639 vulnerabilities (CVEs) — page 22 · VulnSea