VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

667 CVEsRSS

CVE-2026-93991High· 7.7
1w ago

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. A…

▾ Twilightargoproj · argo-workflowsEPSS 0.44%via NVD
CVE-2026-92420Low· 3.8
1w ago

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking…

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-92421Medium· 4.7
1w ago

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking …

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking …

▾ SunlitEPSS 0.29%via NVD
CVE-2026-92425Medium· 5.5
1w ago

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-as…

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-as…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-91847Medium· 4.8
1w ago

The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthentica…

The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthentica…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-89333Medium· 6.5
1w ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…

▾ Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.46%via NVD
CVE-2026-76901Medium· 5.8
1w ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{id} in PoolClueController.get and GET /pool/account/get/{id} in PoolCustomerController.g…

▾ Sunlit1Panel-dev · CordysCRMEPSS 0.40%via NVD
CVE-2026-63647Critical· 9.3PoC
1w ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFi…

▾ Abyssal1Panel-dev · CordysCRMEPSS 0.50%via NVD
CVE-2026-81182Medium· 4.2
1w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by updating the shared…

▾ SunlitSyslifters · sysreptorEPSS 0.27%via NVD
CVE-2026-62279High· 7.1
1w ago

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles endpoint while naming…

▾ Twilighthargata · lubelogEPSS 0.40%via NVD
CVE-2026-77385Medium· 4.3PoC
1w ago

Kyoo is a self-hosted media server focused on movies, series, and anime

Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src…

▾ Twilightzoriya · KyooEPSS 0.34%via NVD
CVE-2026-63458High· 7.1
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on projec…

▾ Twilightperses · persesEPSS 0.30%via NVD
CVE-2026-93758High· 8.1
1w ago

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a requ…

▾ Twilightmongodb · mongoidEPSS 0.36%via NVD
CVE-2026-81505High· 7.1PoC
1w ago

Convoy is a cloud native webhooks gateway

Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() a…

▾ Midnightfrain-dev · github.com/frain-dev/convoyEPSS 0.46%via NVD
CVE-2026-77240Critical· 9.9PoC
1w ago

WACRM is a self-hostable CRM template for WhatsApp

WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role a…

▾ AbyssalArnasDon · wacrmEPSS 0.35%via NVD
CVE-2026-93736Medium· 4.3PoC
1w ago

Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path

Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path. Attackers ca…

▾ Twilightmealie-recipes · mealieEPSS 0.39%via NVD
CVE-2026-93660Medium· 6.5
1w ago

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to…

▾ Sunlitdataease · SQLBotEPSS 0.43%via NVD
CVE-2026-13471Medium· 4.3
1w ago

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to …

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to …

▾ Sunlitlatepoint · Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressEPSS 0.33%via NVD
CVE-2026-12384High· 8.8
1w ago

Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor was contacted early ab…

Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor was contacted early ab…

▾ TwilightTECHIN2B · TECHIN2B ApplicationEPSS 0.31%via NVD
CVE-2026-92714Medium· 6.5
1w ago

The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init

The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic…

▾ Sunlitcodename065 · Download ManagerEPSS 0.41%via NVD
CVE-2026-88844Low· 2.7
1w ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the course before returning its enrolled-student data, allowing users with the MasterStudy LMS WordPress Plugin WordPress…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-87966Medium· 5.3
1w ago

The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied i…

The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied i…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-85009Medium· 6.5
1w ago

The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverabl…

The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to enumerate which orders are in a recoverabl…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-81340Low· 3.8
1w ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-68493Low· 3.1
1w ago

After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

▾ SunlitNextcloud · ServerEPSS 0.23%via NVD
CVE-2026-18441Medium· 4.3
1w ago

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missi…

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missi…

▾ Sunlitlatepoint · Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressEPSS 0.24%via NVD
CVE-2026-69865Critical· 10.0
1w ago

Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Container RegistryEPSS 0.81%via NVD
CVE-2026-54671High· 8.8PoC
1w ago

WeGIA is a web manager for charitable institutions

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as uncondi…

▾ MidnightLabRedesCefetRJ · WeGIAEPSS 0.57%via NVD
CVE-2026-54239High· 8.8
1w ago

Faust.js is a headless WordPress toolkit

Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\Auth\encrypt() an…

▾ Twilightwpengine · faustjsEPSS 0.32%via NVD
CVE-2026-73999Medium· 5.4
1w ago

Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.

Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.

▾ SunlitGora Tech · cookedEPSS 0.29%via NVD
CWE-639 vulnerabilities (CVEs) — page 5 · VulnSea