VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

667 CVEsRSS

CVE-2026-66575Medium· 5.3
1w ago

Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.

Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.

▾ SunlitKingAddons.com · king-addonsEPSS 0.29%via NVD
CVE-2026-82685High· 7.6
1w ago

Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account

Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A confirmation token …

▾ Twilightteam-alembic · ash_authenticationEPSS 0.66%via NVD
CVE-2026-87829Medium· 4.3
1w ago

The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitr…

The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitr…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-91016Medium· 5.3
1w ago

The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private ca…

The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private ca…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-91008Low· 3.7
1w ago

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attend…

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attend…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-61589Medium· 6.3
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFac…

▾ Sunlitdjust-org · djustEPSS 0.18%via NVD
CVE-2026-92577High· 7.5
1w ago

In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers

In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by …

▾ TwilightWWBN · AVideoEPSS 0.43%via NVD
CVE-2026-92588Medium· 4.4
1w ago

n8n is a workflow automation platform

n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead o…

▾ Sunlitn8n-io · n8nEPSS 0.32%via NVD
CVE-2026-61592High· 7.4
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated us…

▾ Twilightdjust-org · djustEPSS 0.39%via NVD
CVE-2026-61596High· 7.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the…

▾ Twilightdjust-org · djustEPSS 0.33%via NVD
CVE-2026-63506High· 8.8PoC
1w ago

Tina is a headless content management system

Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected Tin…

▾ Midnighttinacms · tinacmsEPSS 0.52%via NVD
CVE-2026-92752High· 8.3PoC
1w ago

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace,…

▾ Midnightmetasfresh · metasfreshEPSS 0.46%via NVD
CVE-2026-92773High· 7.1
1w ago

Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization

Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and sup…

▾ Twilighttriggerdotdev · trigger.devEPSS 0.32%via NVD
CVE-2026-92765Medium· 6.5PoC
1w ago

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to r…

▾ Twilightarcherysec · archerysecEPSS 0.45%via NVD
CVE-2026-92809Medium· 4.3PoC
1w ago

PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer

PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for …

▾ TwilightPrestaShop · psgdprEPSS 0.34%via NVD
CVE-2026-92810Medium· 4.3PoC
1w ago

PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier

PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential…

▾ TwilightPrestaShop · blockwishlistEPSS 0.34%via NVD
CVE-2026-87113Medium· 6.3
1w ago

Tanium addressed an improper access controls vulnerability in Threat Response.

Tanium addressed an improper access controls vulnerability in Threat Response.

▾ SunlitTanium · Threat ResponseEPSS 0.26%via NVD
CVE-2026-92716Critical· 9.6PoC
1w ago

Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations

Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with …

▾ AbyssalShuffle · ShuffleEPSS 0.43%via NVD
CVE-2026-92605Medium· 6.5
1w ago

IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items

IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to any single case can enumerate sequential object identifiers and r…

▾ Sunlitdfir-iris · iris-webEPSS 0.41%via NVD
CVE-2026-47094High· 8.8PoC
1w ago

SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation

SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing server-side ownership validation. Attackers can send a P…

▾ MidnightSIMAC · MyPHREPSS 0.51%via NVD
CVE-2026-92603Medium· 6.5PoC
1w ago

ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements

ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message…

▾ Twilightcontinew-org · continew-adminEPSS 0.47%via NVD
CVE-2026-20342High· 7.7
1w ago

A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability exists because user input is not being …

A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability exists because user input is not being …

▾ TwilightCisco · Cisco Secure Firewall Management Center (FMC)EPSS 0.55%via NVD
CVE-2026-89031Medium· 5.4
1w ago

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_pos…

▾ SunlitAdenion · Blog2SocialEPSS 0.30%via NVD
CVE-2026-92567Medium· 6.5
1w ago

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submi…

▾ SunlitTDuckCloud · tduck-survey-formEPSS 0.42%via NVD
CVE-2026-84860High· 8.8
1w ago

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-met…

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-met…

▾ TwilightScada-LTS · Scada-LTSEPSS 0.48%via NVD
CVE-2026-89029Medium· 4.3
1w ago

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the own…

▾ SunlitAdenion · Blog2SocialEPSS 0.28%via NVD
CVE-2026-92469High· 8.1PoC
1w ago

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifie…

▾ Midnightzlt2000 · microservices-platformEPSS 0.54%via NVD
CVE-2026-92468Medium· 6.5PoC
1w ago

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{in…

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{in…

▾ Twilightzlt2000 · microservices-platformEPSS 0.48%via NVD
CVE-2026-86465Medium· 6.5
1w ago

Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key

Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separat…

▾ Sunlitapache · apache-airflow-providers-akeylessEPSS 0.81%via NVD
CVE-2026-88910Medium· 5.3
1w ago

The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers.

The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers.

▾ SunlitEPSS 0.30%via NVD
CWE-639 vulnerabilities (CVEs) — page 6 · VulnSea