VulnSea

CWE-639

CVEs classified under CWE-639, newest first.

668 CVEsRSS

CVE-2026-90517Medium· 5.3PoC
2w ago

A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0

A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack ma…

▾ TwilightPHPGurukul · Bank Locker Management SystemEPSS 0.57%via NVD
CVE-2026-90598Medium· 6.3PoC
2w ago

A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2

A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipu…

▾ Twilightjaygajera17 · E-commerce-project-springBootEPSS 0.39%via NVD
CVE-2026-90542Medium· 5.4PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create scheduler reminders …

▾ TwilightWWBN · AVideoEPSS 0.24%via NVD
CVE-2026-90534Medium· 6.5
2w ago

Flowise is a low-code platform for building LLM applications

Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods w…

▾ Sunlitflowiseai · flowiseEPSS 0.37%via NVD
CVE-2026-90552Medium· 4.3PoC
2w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to r…

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to r…

▾ TwilightWWBN · AVideoEPSS 0.36%via NVD
CVE-2026-87894Medium· 5.3
2w ago

The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing…

The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-84025Low· 2.2
2w ago

The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product i…

The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product i…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-82851Low· 2.7
2w ago

The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitr…

The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitr…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-77705High· 7.2
2w ago

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia'…

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia'…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-89694High· 7.0
2w ago

kernel: nfsd: check client ownership when cancelling a copy-notify stateid (CVE-2026-89694)

A flaw was found in the Linux kernel's NFSv4.2 server (nfsd). An authenticated NFSv4.2 client could exploit a vulnerability in the `manage_cpntf_state()` function by guessing a state identifier. This improper ownership check allows the cli…

▾ TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-81916Medium· 4.3
2w ago

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route. As a result, a user permitted to add entries to o…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.27%via NVD
CVE-2026-81915Medium· 5.3
2w ago

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEdi…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.29%via NVD
CVE-2026-62140Medium· 5.3
2w ago

WordPress Quiz And Survey Master plugin <= 11.2.5 - Insecure Direct Object References (IDOR) vulnerability

Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.

▾ SunlitExpressTech Systems · quiz-master-nextEPSS 0.31%via CVEORG
CVE-2026-62113Medium· 4.3
2w ago

WordPress Slim SEO plugin <= 4.10.0 - Insecure Direct Object References (IDOR) vulnerability

Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions.

▾ SunlitAnh Tran · slim-seoEPSS 0.27%via CVEORG
CVE-2026-54258Medium· 6.5PoC
2w ago

ZoneMinder is a free, open source closed-circuit television software application

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to …

▾ TwilightZoneMinder · zoneminderEPSS 0.34%via NVD
CVE-2026-89262High· 7.5PoC
2w ago

MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary commen…

▾ Midnightmoxi624 · MoguBlogEPSS 0.54%via CVEORG
CVE-2026-62134Medium· 4.3
2w ago

WordPress Starter Templates plugin <= 4.7.5 - Insecure Direct Object References (IDOR) vulnerability

Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions.

▾ SunlitBrainstorm Force · astra-sitesEPSS 0.25%via CVEORG
CVE-2026-89252Medium· 6.5PoC
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's…

▾ TwilightWWBN · AVideoEPSS 0.31%via NVD
CVE-2026-89257Medium· 5.4PoC
2w ago

AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php

AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the …

▾ TwilightWWBN · AVideoEPSS 0.30%via NVD
CVE-2026-14566Medium· 4.3
2w ago

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a sub…

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a sub…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-18121Medium· 6.3
2w ago

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-86782Medium· 5.5
2w ago

The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do n…

The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do n…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-82305Medium· 5.3
2w ago

The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.

The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.

▾ SunlitEPSS 0.30%via NVD
CVE-2026-82213Medium· 5.3
2w ago

The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token referenc…

The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token referenc…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-89264Medium· 4.3PoC
2w ago

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the re…

▾ Twilightmoxi624 · MoguBlogEPSS 0.37%via NVD
CVE-2026-49464High· 8.1
2w ago

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to …

▾ Twilightnl-portal · nl-portal-backend-librariesEPSS 0.35%via NVD
CVE-2026-88865High· 8.1
2w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exc…

▾ TwilightWWBN · AVideoEPSS 0.36%via NVD
CVE-2026-81210High· 7.7
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal

IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained t…

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.34%via NVD
CVE-2026-80434High· 7.4
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.31%via NVD
CVE-2026-88877Critical· 9.8PoC
2w ago

Traefik is a HTTP reverse proxy and load balancer

Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-…

▾ Abyssaltraefik · traefikEPSS 0.65%via NVD
CWE-639 vulnerabilities (CVEs) — page 8 · VulnSea