VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

667 CVEsRSS

CVE-2026-86938High· 7.3
4d ago

A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory

A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability…

▾ TwilightClaris · FileMaker ProEPSS 0.10%via NVD
CVE-2026-86934Critical· 9.1
4d ago

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing …

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing …

▾ MidnightClaris · FileMaker ServerEPSS 0.33%via NVD
CVE-2026-92419Medium· 5.3
4d ago

WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint

WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedPeople parameter in the Gantt vacation chart API does not validate whether the requesting user is authorized to access…

▾ SunlitWEBCON · WEBCON BPSEPSS 0.31%via NVD
CVE-2026-55610High· 8.7
4d ago

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates

InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.4.1, in InvoiceShelf's multi-company installations, any user who is an Owner of one co…

▾ TwilightInvoiceShelf · InvoiceShelfEPSS 0.30%via NVD
CVE-2026-86678High· 8.8
4d ago

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.

▾ TwilightZohocorp · ManageEngine Applications ManagerEPSS 0.68%via NVD
CVE-2026-84791High· 7.1
4d ago

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule confi…

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule confi…

▾ TwilightZohocorp · ManageEngine OpManagerEPSS 0.60%via NVD
CVE-2026-84789High· 7.1
4d ago

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outsi…

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outsi…

▾ TwilightZohocorp · ManageEngine OpManagerEPSS 0.60%via NVD
CVE-2026-91025Medium· 4.3
4d ago

The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated…

The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-84150Medium· 5.4
4d ago

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches the authenticated caller before reading and modifying that user's saved …

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches the authenticated caller before reading and modifying that user's saved …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-81339Medium· 4.3
4d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other stude…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other stude…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-80342Medium· 6.5
4d ago

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, …

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, …

▾ SunlitEPSS 0.20%via NVD
CVE-2026-77766Medium· 4.3
4d ago

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read ev…

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read ev…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-16264Medium· 6.5
4d ago

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subsc…

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subsc…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-96271High· 7.1
4d ago

Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users

Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to …

▾ Twilightphotoview · photoviewEPSS 0.23%via NVD
CVE-2026-57168Critical· 9.6
4d ago

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-56120. Reason: This candidate is a duplicate of CVE-2026-56120. Notes: All CVE users should reference CVE-2026-56120 instead of this candidate.

▾ Midnightopenremote · io.openremote:openremote-managervia NVD
CVE-2026-75101Medium· 6.0
5d ago

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tok…

▾ SunlitGitHub · Enterprise ServerEPSS 0.45%via NVD
CVE-2026-76910Medium· 5.3PoC
5d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:projectId/features/:featureName/clone authorize creation in the destination project but do not verify access to the s…

▾ TwilightUnleash · unleashEPSS 0.30%via NVD
CVE-2026-77426High· 7.1
5d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/admin/segments/strategies assigns the Promise returned by hasPermission without awaiting …

▾ TwilightUnleash · unleashEPSS 0.48%via NVD
CVE-2026-77425Medium· 4.3PoC
5d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUp…

▾ TwilightUnleash · unleashEPSS 0.23%via NVD
CVE-2026-83805Medium· 6.4
5d ago

Nautobot is a Network Source of Truth and Network Automation Platform

Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, change permission on the object under re…

▾ Sunlitnautobot · nautobotEPSS 0.22%via NVD
CVE-2026-94462High· 7.1PoC
5d ago

Spree is an open source e-commerce solution built with Ruby on Rails

Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::V3::Store::CartsController#associate uses find_cart_for_association to locate …

▾ Midnightspree_api · spree_apiEPSS 0.28%via NVD
CVE-2026-95655High· 8.1
5d ago

Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages

Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages f…

▾ Twilightaureuserp · aureuserpEPSS 0.49%via NVD
CVE-2026-75517Medium· 6.5
5d ago

Novu provides an API for sending notifications through multiple channels

Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use cases including remove-integration, update-integration, auto-configure-integration, and set-integration-as-primary l…

▾ Sunlitnovuhq · novuEPSS 0.70%via NVD
CVE-2026-95683Medium· 5.3
5d ago

In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes

In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched the report using only the event ID as the lookup condition, without applying the report's own dist…

▾ SunlitMISP · MISPEPSS 0.39%via NVD
CVE-2026-93556Critical· 9.3
5d ago

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parame…

▾ MidnightKompini · Tankuam PlacesEPSS 0.30%via NVD
CVE-2026-12995Medium· 4.3
5d ago

The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value due to missing validation on a user controlled key

The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value due to missing validation on a user controlled key. This makes it possib…

▾ Sunlithiroaki-miyashita · Custom Field TemplateEPSS 0.21%via NVD
CVE-2026-18439Medium· 4.3
5d ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.7 via the tutor_quiz_builder_save AJAX action due to missing validation tha…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.7 via the tutor_quiz_builder_save AJAX action due to missing validation tha…

▾ Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.25%via NVD
CVE-2026-94536Medium· 4.3PoC
6d ago

lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions

lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions. Attackers can supply arbitrary employeeId values to…

▾ Twilightdromara · lamp-cloudEPSS 0.34%via NVD
CVE-2026-94532Medium· 6.5PoC
6d ago

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can iterate the userId parameter to harvest sensiti…

▾ Twilightdromara · lamp-cloudEPSS 0.44%via NVD
CVE-2026-94535High· 7.1PoC
6d ago

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNoti…

▾ Midnightdromara · lamp-cloudEPSS 0.47%via NVD
CWE-639 vulnerabilities (CVEs) — page 3 · VulnSea