VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1329 CVEsRSS

CVE-2026-50025Medium· 6.9
2w ago

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN prove…

▾ Sunlitt-mart · mouseholeEPSS 0.26%via NVD
CVE-2026-90448High· 7.1
2w ago

A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed

A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwr…

▾ TwilightCISA · MalcolmEPSS 0.35%via NVD
CVE-2026-8304Medium· 5.5
2w ago

Information Disclosure in TUBITAK BILGEM's Pardus About

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus About: from 1.2.1 before 1.2.5.

▾ SunlitTUBITAK BILGEM Software Technologies Research Institute · Pardus AboutEPSS 0.14%via CVEORG
CVE-2026-81909Medium· 5.9
2w ago

Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks

Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the t…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.44%via CVEORG
CVE-2026-81908Medium· 6.0
2w ago

Missing Authorization in Concrete CMS 9.2.0 to 9.5.2 REST API Groups List Endpoint Allows Authenticated Users to Enumerate All Groups

Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditional…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.39%via CVEORG
CVE-2026-72709Critical· 9.8PoC
2w ago

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any serve…

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any serve…

▾ AbyssalSPIP · SPIPEPSS 0.66%via NVD
CVE-2026-18121Medium· 6.3
2w ago

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-56828High· 8.8
2w ago

Shopper: privilege escalation via improper Livewire admin component authorization

Shopper: privilege escalation via improper Livewire admin component authorization

▾ Twilightshopper · shopper/frameworkvia GHSA
CVE-2026-56826Medium· 5.4
2w ago

Shopping privilege escalation through missing authorization in Settings components

Shopping privilege escalation through missing authorization in Settings components

▾ Sunlitshopper · shopper/frameworkvia GHSA
CVE-2026-38056High· 8.8
2w ago

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the pri…

▾ TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.15%via NVD
CVE-2026-86815Medium· 5.5
2w ago

The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.…

The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-86779Low· 2.7
2w ago

The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above…

The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-11446Medium· 5.3
2w ago

The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23

The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23. This is due to the create_order_permission() pe…

▾ Sunlitarraytics · Booktics – Appointment Booking Calendar for Service BusinessesEPSS 0.24%via NVD
CVE-2026-49439Medium· 4.3
2w ago

OpenRemote is an open-source internet-of-things platform

OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.

▾ Sunlitopenremote · openremoteEPSS 0.26%via NVD
CVE-2026-81211High· 8.8
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.

▾ Twilightlangflow · langflowEPSS 0.50%via NVD
CVE-2026-4129High· 8.1
2w ago

There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted

There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects N…

▾ TwilightNI · SystemLinkEPSS 0.35%via NVD
CVE-2026-15823Medium· 4.3
2w ago

Builderall for WordPress <= 3.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'ba_cheetah_data[post_id]' Parameter

The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disable() function in versions up to, and including, 3.0.2. The wp_ajax_ba_cheetah_disable AJA…

▾ Sunlitbuilderall · Builderall for WordPressEPSS 0.20%via CVEORG
CVE-2026-88959High· 8.8
2w ago

Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints

Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify existing ones. Attackers with editor or use…

▾ Twilightanchorcms · anchorcms/anchor-cmsEPSS 0.52%via CVEORG
CVE-2026-88271High· 8.8
2w ago

GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.

GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.42%via NVD
CVE-2026-81793Medium· 6.5
2w ago

WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.

▾ SunlitDimitri Grassi · salon-booking-systemEPSS 0.33%via CVEORG
CVE-2026-81786High· 7.5
2w ago

WordPress Thank You Page Customizer for WooCommerce plugin <= 1.2.2 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.

▾ TwilightVillaTheme · woo-thank-you-page-customizerEPSS 0.39%via CVEORG
CVE-2026-88915High· 7.1
2w ago

Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id

Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed …

▾ TwilightMISP · MISPEPSS 0.35%via NVD
CVE-2026-14873High· 8.0
2w ago

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating th…

▾ Twilightrubenw · Bulk Password ResetEPSS 0.23%via NVD
CVE-2026-89054High· 8.2
2w ago

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the ship…

▾ TwilightThe OpenNMS Group · HorizonEPSS 0.51%via NVD
CVE-2026-88270Medium· 6.5
2w ago

GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of Service

GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.37%via CVEORG
CVE-2026-81801High· 8.1
2w ago

WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability

Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.

▾ TwilightUDX Usability Dynamics · wp-statelessEPSS 0.38%via CVEORG
CVE-2026-81794High· 7.5
2w ago

WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.

▾ Twilightmlfactory · woo-shirt-product-designerEPSS 0.35%via CVEORG
CVE-2026-88898Medium· 6.5PoC
2w ago

AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces

AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published…

▾ TwilightAppFlowy-IO · AppFlowy-CloudEPSS 0.39%via NVD
CVE-2026-81799High· 7.5
2w ago

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.

▾ TwilightWP Swings · woo-refund-and-exchange-liteEPSS 0.35%via NVD
CVE-2026-81788Medium· 6.3
2w ago

Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.

Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.

▾ SunlitIDX Broker · idx-broker-platinumEPSS 0.26%via NVD
CWE-862 vulnerabilities (CVEs) — page 16 · VulnSea