VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2026-66061High· 7.1
1mo ago

Home Assistant is open source home automation software focused on local control and privacy

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism such as iOS universal lin…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-66060High· 7.1
1mo ago

Home Assistant is open source home automation software focused on local control and privacy

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism as if they were physically s…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-64676Medium· 5.7
1mo ago

Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers

Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vulnerable to an authorization bypass in confidential-guest memory managem…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-47127Medium· 6.5
1mo ago

Ghostfolio is an open source wealth management software

Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/subscription/stripe/callback?checkoutSessionId=<id>` retrieves the Stripe Checkout Session …

▾ SunlitEPSS 0.34%via NVD
CVE-2026-66058None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.

▾ SunlitEPSS 0.38%via NVD
CVE-2026-11907Medium· 6.5
1mo ago

The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0

The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible fo…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-48169High· 8.8
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key…

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.44%via NVD
CVE-2026-67621High· 7.6
1mo ago

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-l…

▾ Twilightflowiseai · flowiseEPSS 0.42%via NVD
CVE-2026-48085Critical· 9.8
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-…

▾ MidnightEPSS 0.59%via NVD
CVE-2026-48077Medium· 5.3
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no authorization check befor…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-48075Medium· 6.5
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any client tunnel without any caller authen…

▾ SunlitEPSS 0.42%via NVD
CVE-2026-47765None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate document permission checks, allowing an authenticated user to restore deleted documents …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-65667Critical· 10.0
1mo ago

Microsoft Teams Elevation of Privilege Vulnerability

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft TeamsEPSS 0.80%via CVEORG
CVE-2026-62830Critical· 9.9
1mo ago

Azure SRE Agent Elevation of Privilege Vulnerability

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure SRE AgentEPSS 0.78%via CVEORG
CVE-2026-70636High· 7.5
1mo ago

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware d…

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware d…

▾ Twilightflowiseai · flowiseEPSS 0.66%via NVD
CVE-2026-48088Critical· 9.4
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML…

▾ MidnightEPSS 0.38%via NVD
CVE-2026-66701Medium· 5.3
1mo ago

Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.

Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.

▾ SunlitEPSS 0.29%via NVD
CVE-2026-66452Medium· 6.5
1mo ago

Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.

Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.

▾ SunlitEPSS 0.33%via NVD
GHSA-rvmm-v933-jgxqMedium
1mo ago

Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics

Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-14793Medium· 4.3
1mo ago

Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

▾ Sunlitcraftcms · craftcms/cmsEPSS 0.39%via GHSA
CVE-2026-64664Medium· 4.3
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belo…

▾ Sunlitstatamic · statamic/cmsEPSS 0.34%via NVD
CVE-2026-64662Medium· 6.5
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and cust…

▾ Sunlitstatamic · statamic/cmsEPSS 0.41%via NVD
CVE-2026-45415Medium· 6.0
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_census/census_logs record-management endpoints do not enforce full administrator authorizatio…

▾ Sunlitdecidim-verifications · decidim-verificationsEPSS 0.43%via NVD
CVE-2026-70618Medium· 4.3
1mo ago

Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint wit…

Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint wit…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-70617High· 8.1
1mo ago

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint with…

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint with…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-48168Critical· 10.0
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block …

▾ MidnightEPSS 1.5%via NVD
CVE-2026-54418High· 8.1
1mo ago

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permissi…

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permissi…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-71316High· 7.5
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guards because import.meta.prerender is no…

▾ Twilightnuxt · nuxtEPSS 0.51%via NVD
CVE-2026-70619High· 8.8PoC
1mo ago

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session auth…

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session auth…

▾ Midnightodysseus-dev · odysseusEPSS 0.66%via NVD
CVE-2026-70494High· 8.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a sha…

▾ Twilightopenwebui · open_webuiEPSS 0.55%via NVD
CWE-862 vulnerabilities (CVEs) — page 32 · VulnSea