VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1329 CVEsRSS

CVE-2026-84514Medium· 5.5
1w ago

This issue was addressed with additional entitlement checks

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file system.

▾ Sunlitapple · macosEPSS 0.14%via NVD
CVE-2026-16190Low· 3.1
1w ago

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.16%via NVD
CVE-2026-16187Medium· 6.5
1w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVE-2026-16185Medium· 6.4
1w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console servlet.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.20%via NVD
CVE-2026-82519Medium· 4.3
1w ago

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an u…

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an u…

▾ Sunlitreallysimpleplugins · Really Simple SecurityEPSS 0.36%via NVD
CVE-2026-89023High· 8.6
1w ago

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can ret…

▾ TwilightThemeAtelier · Domain For SaleEPSS 0.39%via NVD
CVE-2026-90806Medium· 6.3
1w ago

A vulnerability has been found in DjangoCRM django-crm up to 1.2

A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing au…

▾ SunlitDjangoCRM · django-crmEPSS 0.37%via NVD
CVE-2026-57578Critical· 9.2
1w ago

DotVVM is an open source MVVM framework for web applications

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFilter.OnCommandExecutingAsync, IViewMod…

▾ Midnightriganti · dotvvmEPSS 0.62%via NVD
CVE-2026-57579High· 7.5PoC
1w ago

Alchemy is an open source content management system engine written in Ruby on Rails

Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, and 8.2.6, the unauthenticated GET /api/pages/nested endpoint implemented by Api::PagesController#nested in app/control…

▾ MidnightAlchemyCMS · alchemy_cmsEPSS 0.65%via NVD
CVE-2026-90895High· 8.4
1w ago

Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web applicat…

Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web applicat…

▾ TwilightMISP · MISPEPSS 0.15%via NVD
CVE-2026-14259Medium· 4.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or P…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or P…

▾ SunlitMattermost · MattermostEPSS 0.15%via NVD
CVE-2026-8821High· 7.1
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrar…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrar…

▾ TwilightMattermost · MattermostEPSS 0.29%via NVD
CVE-2026-14344Medium· 4.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-…

▾ SunlitMattermost · MattermostEPSS 0.15%via NVD
CVE-2026-75030Critical· 9.8
1w ago

Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue…

Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue…

▾ MidnightApache Software Foundation · org.apache.syncope.core.idrepo:syncope-core-idrepo-logicEPSS 0.62%via NVD
CVE-2026-82437Medium· 4.3
1w ago

Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content

Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For daemon logs those settings were not applied: the access decision combined the "this is a daemon log" flag with the au…

▾ SunlitApache Software Foundation · org.apache.storm:storm-webappEPSS 0.28%via NVD
CVE-2026-82433Medium· 6.5
1w ago

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and t…

▾ SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.34%via NVD
CVE-2026-90941Medium· 4.3PoC
1w ago

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookI…

▾ Twilight201206030 · novel-plusEPSS 0.41%via NVD
CVE-2026-90939Medium· 6.5PoC
1w ago

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email add…

▾ Twilight201206030 · novel-plusEPSS 0.46%via NVD
CVE-2026-90933High· 7.1PoC
1w ago

laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys

laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged ac…

▾ Midnightlaradashboard · laradashboardEPSS 0.30%via NVD
CVE-2026-57570Medium· 6.5
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.15 and 7.0.47, HasMany and MorphMany handling t…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.44%via NVD
CVE-2026-57131Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.97%via NVD
CVE-2026-53718Medium· 6.4
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resour…

▾ Sunlitenvoyproxy · gatewayEPSS 0.41%via NVD
CVE-2026-54628High· 8.6PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without …

▾ Midnightjulien040 · anyqueryEPSS 0.60%via NVD
CVE-2026-54629High· 7.5
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, a…

▾ Twilightjulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-50006Critical· 9.1PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacke…

▾ Abyssaljulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-90768High· 8.1
2w ago

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary…

▾ Twilightkevoreilly · CAPEv2EPSS 0.43%via NVD
CVE-2026-90508Low· 3.4PoC
2w ago

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Pe…

▾ TwilightChengdu Qilu Technology · LudashiEPSS 0.16%via NVD
CVE-2026-90599Medium· 4.3PoC
2w ago

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forg…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.24%via NVD
CVE-2026-90595Medium· 6.3PoC
2w ago

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation res…

▾ Twilightwxiaoqi · Spring-Cloud-PlatformEPSS 0.37%via NVD
CVE-2026-90594Medium· 6.3PoC
2w ago

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Servic…

▾ Twilightwxiaoqi · Spring-Cloud-PlatformEPSS 0.37%via NVD
CWE-862 vulnerabilities (CVEs) — page 14 · VulnSea