VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2026-42142High· 7.1
1mo ago

TypeBot is a chatbot builder tool

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace'…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-58237Medium· 5.9
1mo ago

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality

WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker…

▾ Sunlitsap · approuterEPSS 0.28%via NVD
CVE-2026-70340High· 8.1
1mo ago

Azure CycleCloud Elevation of Privilege Vulnerability

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Azure CycleCloud 8.9.1EPSS 0.80%via CVEORG
CVE-2026-40375Medium· 6.5
1mo ago

Microsoft Dynamics Business Central Information Disclosure Vulnerability

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft Dynamics 365 Business Central 2024 Release Wave 2EPSS 0.84%via CVEORG
CVE-2026-62915Medium· 6.5
1mo ago

Microsoft Exchange Server Security Feature Bypass Vulnerability

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

▾ SunlitMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.64%via CVEORG
CVE-2026-65806Medium· 6.5
1mo ago

Azure CycleCloud Information Disclosure Vulnerability

Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Azure CycleCloud 8.9.2EPSS 0.84%via CVEORG
CVE-2026-18709Medium· 6.4
1mo ago

An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process

An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could res…

▾ Sunlitmongodb · mongodbEPSS 0.19%via NVD
CVE-2026-18704Medium· 6.5
1mo ago

An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify

An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation …

▾ Sunlitmongodb · mongodbEPSS 0.20%via NVD
CVE-2026-65675High· 7.1
1mo ago

No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.

No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.

▾ Twilightmicrosoft · github_copilot_chatEPSS 0.64%via NVD
CVE-2026-59113High· 8.8
1mo ago

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · visual_studio_codeEPSS 0.76%via NVD
CVE-2026-61936Medium· 5.5
1mo ago

Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.

Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.

▾ Sunlitmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-71959Medium· 5.8
1mo ago

Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organiza…

Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organiza…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-72919Medium· 4.3
1mo ago

Rocket.Chat is an open-source, secure, fully customizable communications platform

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the channels.convertToTeam REST endpoint allows an authenticated registered user wi…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-72918Medium· 5.4
1mo ago

Rocket.Chat is an open-source, secure, fully customizable communications platform

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the WebSocket protocol allows an authenticated use…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-72910High· 7.1
1mo ago

ERPNext is a free and open source Enterprise Resource Planning tool

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across erpnext/accounts/…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-47754Critical· 9.3
1mo ago

Metacat is data repository software that helps researchers preserve, share, and discover data

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=…

▾ MidnightEPSS 0.47%via NVD
CVE-2026-72906Medium· 4.3
1mo ago

ERPNext is a free and open source Enterprise Resource Planning tool

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process S…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-72883High· 8.8
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/server/wss/terminal.ts, apps/dokploy/server/wss/docker-container-terminal.ts, apps/dokploy/server/wss/docker-containe…

▾ TwilightEPSS 0.57%via NVD
CVE-2026-72876Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s server…

▾ MidnightEPSS 0.71%via NVD
CVE-2026-72868Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, and bucket fields from destination.t…

▾ MidnightEPSS 0.71%via NVD
CVE-2026-72866High· 8.8
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/server/wss/terminal.ts validates a session but does not authorize access to the requested server. An authenticated use…

▾ TwilightEPSS 0.57%via NVD
CVE-2026-72864Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-terminal in apps/dokploy/server/wss/docker-container-terminal.ts authenticates with validateRequest but does not autho…

▾ MidnightEPSS 0.51%via NVD
CVE-2026-72863Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via valida…

▾ MidnightEPSS 0.55%via NVD
CVE-2026-72737Critical· 9.6
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accept a client-controlled destinationId an…

▾ MidnightEPSS 0.35%via NVD
CVE-2026-72732Medium· 4.3
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_templates endpoint exposed hidden tag names because DiscourseTemplates::TemplatesSerializer in plugins/discourse-template…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-72723Medium· 5.3
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymous_default_navigation_menu_tags serializes tags from SiteSetting.default_navigation_menu_tags without applying Di…

▾ SunlitEPSS 0.53%via NVD
CVE-2026-72722Medium· 4.3
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_from, TopicLink.ensure_entry_for, and TopicLink.duplicate_lookup do not consistently enforce Guardian.can_see? checks…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-19350Medium· 6.3
1mo ago

A vulnerability has been found in Dolibarr ERP up to 23.0.3

A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be perfor…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-19345Medium· 6.5
1mo ago

A vulnerability was found in code-projects Task Management System 1.0

A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to …

▾ SunlitEPSS 0.55%via NVD
CVE-2026-17601High· 7.2
1mo ago

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, withou…

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, withou…

▾ Twilightsonatype · nexus_repository_managerEPSS 0.29%via NVD
CWE-862 vulnerabilities (CVEs) — page 31 · VulnSea