VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1327 CVEsRSS

CVE-2026-19775Medium· 4.3
2d ago

The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.7

The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying that a user …

▾ Sunlitallterraindeveloper · OpenStation: Desktop Windows, Dock & Virtual Desktops for WP AdminEPSS 0.23%via NVD
CVE-2026-89055Critical· 9.1PoC
2d ago

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an actio…

▾ Abyssalivole · Customer Reviews for WooCommerceEPSS 0.39%via NVD
CVE-2026-92829Medium· 4.3
2d ago

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. This is due to the plugin not properly verifying that a user is authorized to per…

▾ Sunlitpr-gateway · Blog2Social: Social Media Auto Post & SchedulerEPSS 0.32%via NVD
CVE-2026-97648Medium· 4.3PoC
2d ago

A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function. Performing a manipulation results in cross-site request forgery. It is possible to init…

▾ Twilightningzichun · student-management-systemEPSS 0.16%via NVD
CVE-2026-86860Critical· 9.3
3d ago

ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform

ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what wa…

▾ MidnightServiceNow · ServiceNow AI PlatformEPSS 0.30%via NVD
CVE-2026-77293High· 7.1PoC
3d ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/se…

▾ Midnightmauriceboe · TREKEPSS 0.38%via NVD
CVE-2026-77321Medium· 4.3
3d ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and returns core trip summary data regardless of th…

▾ Sunlitmauriceboe · TREKEPSS 0.20%via NVD
CVE-2026-52850Medium· 4.3
3d ago

Docmost is open-source collaborative wiki and documentation software

Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call the transclusion / sync-block lookup API with a known sourcePageId a…

▾ Sunlitdocmost · docmostEPSS 0.19%via NVD
CVE-2026-86857High· 8.4
3d ago

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform th…

▾ TwilightServiceNow · ServiceNow AI PlatformEPSS 0.24%via NVD
CVE-2026-61604Critical· 9.3
3d ago

The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet

The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolve…

▾ Midnightixofoundation · github.com/ixofoundation/ixo-blockchain/v8EPSS 0.27%via NVD
CVE-2026-84302Medium· 4.2
3d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review queue of a moderator who was not a parti…

▾ Sunlitdiscourse · discourseEPSS 0.24%via NVD
CVE-2026-91160High· 8.2
3d ago

OpenWA is a free, open source, self-hosted WhatsApp API gateway

OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers the session.qr event to a VIEWER API key that subscribes by event name or through either wildcard subscription form,…

▾ Twilightrmyndharis · OpenWAEPSS 0.25%via NVD
CVE-2026-79758Medium· 5.4PoC
3d ago

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0 until 2.5.1, authenticated Termix users can access the server-stats API without per-host authorization. GET /status …

▾ TwilightTermix-SSH · TermixEPSS 0.43%via NVD
CVE-2026-67233Medium· 6.0
3d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel management resource's is_authorized/2 delegates to rabbit_mgmt_util:is_authorized_monitor/2, which accepts the monitori…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-63203High· 7.6PoC
3d ago

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller holding a same-user access token with …

▾ Midnightlogto-io · logtoEPSS 0.31%via NVD
CVE-2026-65422Medium· 6.5
3d ago

A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback privileges to generate video thumbnails.

A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback privileges to generate video thumbnails.

▾ SunlitGenetec Inc. · Genetec Security CenterEPSS 0.20%via NVD
CVE-2026-97061Medium· 4.3
3d ago

Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticated user to enumerate all playlists on the instance

Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticated user to enumerate all playlists on the instance. Attackers can query the SearchController or Search::Playlists…

▾ Sunlitblackcandy-org · Black CandyEPSS 0.22%via NVD
CVE-2026-97360Critical· 10.0PoC
3d ago

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …

▾ Abyssalrejetto · hfs2EPSS 0.32%via NVD
CVE-2026-96515High· 8.6PoC
3d ago

This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality

This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. An authenticated attacker could exploit this vulnerability by uplo…

▾ MidnightNetlink ICT Pvt Ltd · Netlink ICT HG323RW RouterEPSS 0.31%via NVD
CVE-2026-97311Medium· 4.3
3d ago

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVE-2026-4806Medium· 6.5
3d ago

The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2

The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes …

▾ Sunlitalexvtn · Custom Thank You Page for WooCommerceEPSS 0.17%via NVD
CVE-2026-3253Medium· 4.3
3d ago

The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1…

The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1…

▾ Sunlitmailerlite · MailerLite – Signup forms (official)EPSS 0.16%via NVD
CVE-2026-97177Medium· 6.6
3d ago

A flaw was found in the user update mechanism of the Keycloak Admin REST API

A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. Thi…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVE-2026-97176Medium· 4.2
3d ago

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an act…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.17%via NVD
CVE-2026-88847Medium· 4.3
3d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create cou…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create cou…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-88846Medium· 5.3
3d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated use…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated use…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-88845Medium· 4.3
3d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-82195Medium· 6.5
3d ago

The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete …

The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete …

▾ SunlitEPSS 0.23%via NVD
CVE-2026-80338Medium· 6.8
3d ago

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break co…

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break co…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-92470High· 7.7
3d ago

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD varia…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD varia…

▾ TwilightGitLab · GitLabEPSS 0.21%via NVD
CWE-862 vulnerabilities (CVEs) — page 3 · VulnSea