VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1329 CVEsRSS

CVE-2026-56830Medium· 6.5
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used …

▾ Sunlitshopperlabs · shopperEPSS 0.39%via NVD
CVE-2026-56829High· 8.1PoC
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable be…

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-56827High· 8.1PoC
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.ph…

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-56825High· 8.1PoC
1w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/CollectionProducts.php exposes Action::make('delete') and DeleteBulkAction::make() without delete_collections authorization, …

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-54168Medium· 6.5
1w ago

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the …

▾ Sunlittektoncd · pipelines-as-codeEPSS 0.59%via NVD
CVE-2026-53966High· 7.1
1w ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who can edit a page to change that page's rights without executing the normal document…

▾ Twilightxwiki · xwiki-platformEPSS 0.77%via NVD
CVE-2026-55178High· 7.5
1w ago

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder

GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a…

▾ Twilightgeolens-io · geolensEPSS 0.65%via NVD
CVE-2026-57112High· 8.3PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legac…

▾ MidnightMervinPraison · PraisonAIEPSS 0.22%via NVD
CVE-2026-54076High· 8.1
1w ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcad…

▾ TwilightArcadeData · arcadedbEPSS 0.50%via NVD
CVE-2026-61549Critical· 9.0
1w ago

Woodpecker is a CI/CD engine

Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pip…

▾ Midnightwoodpecker-ci · woodpeckerEPSS 0.28%via NVD
CVE-2026-52828Medium· 5.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives b…

▾ Sunlitkimai · kimaiEPSS 0.46%via NVD
CVE-2026-52821Medium· 5.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability…

▾ Sunlitkimai · kimaiEPSS 0.43%via NVD
CVE-2026-52822Medium· 5.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned historical timesheet after…

▾ Sunlitkimai · kimaiEPSS 0.46%via NVD
CVE-2026-52825Medium· 5.3
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the ref…

▾ Sunlitkimai · kimaiEPSS 0.45%via NVD
CVE-2026-55863Medium· 5.3PoC
1w ago

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, the ActionHandler.post() method in motioneye/handlers/action.py lacks the Base…

▾ Twilightmotioneye-project · motioneyeEPSS 0.50%via NVD
CVE-2026-77191Low· 2.6
1w ago

An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the …

An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the …

▾ SunlitArista Networks · EOSEPSS 0.22%via NVD
CVE-2026-12758Medium· 5.4
1w ago

IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.

IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.

▾ SunlitIBM · Cloud Pak for Business AutomationEPSS 0.18%via NVD
CVE-2026-56668High· 8.1
1w ago

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange

ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.41%via OSV
CVE-2026-90820Medium· 4.3
1w ago

A security vulnerability has been detected in a2aproject a2a-java 1.2.0

A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandl…

▾ Sunlita2aproject · a2a-javaEPSS 0.39%via NVD
CVE-2026-81901High· 8.7
1w ago

In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce page-property, page-template, or page-type authorization

In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce page-property, page-template, or page-type authorization. A user granted only content-editing rights on a page could th…

▾ Twilightconcretecms · concrete_cmsEPSS 0.38%via NVD
CVE-2026-43689High· 7.8
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. A malicious app may be able to gain root privileges.

▾ Twilightapple · ipadosEPSS 0.15%via NVD
CVE-2026-84629High· 7.5
1w ago

This issue was addressed with additional entitlement checks

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to fingerprint the user.

▾ Twilightapple · ipadosEPSS 0.42%via NVD
CVE-2026-86897Medium· 5.5
1w ago

This issue was addressed with additional entitlement checks

This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. An app may be able to access sensitive user data.

▾ Sunlitapple · safariEPSS 0.15%via NVD
CVE-2026-84551Medium· 4.4
1w ago

A logic issue was addressed with improved validation

A logic issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27, watchOS 27. An app may be able to bypass network restrictions.

▾ Sunlitapple · ipadosEPSS 0.14%via NVD
CVE-2026-65381Critical· 10.0
1w ago

A validation issue existed in the entitlement verification

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious app …

▾ Midnightapple · macosEPSS 0.35%via NVD
CVE-2026-65342High· 7.5⚖ disputed
1w ago

A permissions issue was addressed with improved validation

A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

▾ Twilightapple · macosEPSS 0.31%via NVD
CVE-2026-43789High· 7.5⚖ disputed
1w ago

An access issue was addressed with additional sandbox restrictions

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

▾ Twilightapple · macosEPSS 0.31%via NVD
CVE-2026-43696Medium· 5.3
1w ago

An authorization issue was addressed with improved entitlement checks

An authorization issue was addressed with improved entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to capture Touch Bar content without authorization.

▾ Sunlitapple · macosEPSS 0.29%via NVD
CVE-2026-84569Medium· 5.5
1w ago

An access issue was addressed with additional sandbox restrictions on the system pasteboards

An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.14%via NVD
CVE-2026-84580High· 8.4
1w ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.

▾ Twilightapple · macosEPSS 0.15%via NVD
CWE-862 vulnerabilities (CVEs) — page 13 · VulnSea