VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2026-70481Medium· 5.4PoC
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checki…

▾ Twilightopenwebui · open_webuiEPSS 0.43%via NVD
CVE-2026-70483Low· 3.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the caller could delete that chat. Any au…

▾ Sunlitopenwebui · open_webuiEPSS 0.46%via NVD
CVE-2026-70484Medium· 4.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.i…

▾ Sunlitopenwebui · open_webuiEPSS 0.41%via NVD
CVE-2026-70487Medium· 5.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller's read a…

▾ Sunlitopenwebui · open_webuiEPSS 0.42%via NVD
CVE-2026-70475Medium· 6.5
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware …

▾ Sunlitflowiseai · flowiseEPSS 0.46%via NVD
GHSA-8gj2-2cvc-6xx7Medium
1mo ago

Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials

Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials

▾ Sunlitflowise · flowisevia GHSA
CVE-2026-70473High· 8.5
1mo ago

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requestin…

▾ Twilightflowiseai · flowiseEPSS 0.45%via NVD
CVE-2026-69252High· 8.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A lo…

▾ Twilightflowiseai · flowiseEPSS 0.54%via NVD
CVE-2026-69090Medium· 4.9
1mo ago

Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations

Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a r…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-66311Medium· 6.2
1mo ago

Microsoft Edge (Chromium-based) Tampering Vulnerability

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.40%via CVEORG
CVE-2026-66326Medium· 6.5
1mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.77%via CVEORG
CVE-2026-20483None
1mo ago

In Telephony, there is a possible escalation of privilege due to a missing permission check

In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-18573Medium· 6.5
1mo ago

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication…

▾ Sunlitredhat · build_of_keycloakEPSS 0.48%via NVD
CVE-2026-18571Medium· 6.6
1mo ago

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups t…

▾ Sunlitredhat · build_of_keycloakEPSS 0.55%via NVD
CVE-2026-18570Medium· 5.4
1mo ago

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Key…

▾ Sunlitredhat · build_of_keycloakEPSS 0.30%via NVD
CVE-2026-67344Medium· 4.3
1mo ago

ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ..

ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStrategy in LocalDocu…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-17580Medium· 6.5
1mo ago

The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

▾ SunlitEPSS 0.55%via NVD
CVE-2026-11995Medium· 5.3
1mo ago

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.9.0

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.9.0. This is due to the plugin not prop…

▾ SunlitEPSS 0.56%via NVD
CVE-2026-10782Medium· 4.3
1mo ago

The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.9

The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-3141Critical· 9.1
1mo ago

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This i…

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This i…

▾ MidnightEPSS 0.90%via NVD
CVE-2026-18218Medium· 4.2
1mo ago

A flaw was found in the TokenManager component of the Keycloak identity management service

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" policy, the revocation may be silently i…

▾ Sunlitredhat · build_of_keycloakEPSS 0.29%via NVD
CVE-2026-18208Medium· 6.5
1mo ago

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a con…

▾ Sunlitredhat · build_of_keycloakEPSS 0.34%via NVD
CVE-2026-16105Medium· 4.9
1mo ago

A flaw was found in the RoleContainerResource component of Keycloak

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a de…

▾ Sunlitredhat · build_of_keycloakEPSS 0.42%via NVD
CVE-2026-18214Medium· 6.8
1mo ago

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloa…

▾ Sunlitredhat · build_of_keycloakEPSS 0.40%via NVD
CVE-2026-45086Medium· 5.4
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a participant can directly load /admin/demographics/questions/edit_questions and reach the demographics questionnaire editor w…

▾ Sunlitdecidim-demographics · decidim-demographicsEPSS 0.29%via NVD
CVE-2026-45330Medium· 4.9
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin controllers load pending Authorization records by raw identifier wi…

▾ Sunlitdecidim-verifications · decidim-verificationsEPSS 0.46%via NVD
CVE-2026-18201Medium· 5.5
2mo ago

Keycloak provides a way to manage identity providers and organizations through its administrative API

Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization…

▾ Sunlitredhat · build_of_keycloakEPSS 0.38%via NVD
CVE-2026-52839Low· 3.3
2mo ago

Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass

Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass

▾ Sunlitalextselegidis · alextselegidis/easyappointmentsEPSS 0.23%via GHSA
GHSA-pc2w-4mq8-32qwLow· 3.7
2mo ago

@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate

@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate

▾ Sunlitdynatrace-oss · @dynatrace-oss/dynatrace-mcp-servervia GHSA
CVE-2026-54719High· 7.5
2mo ago

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

▾ Twilightpatrickhener · github.com/patrickhener/goshsEPSS 0.47%via GHSA
CWE-862 vulnerabilities (CVEs) — page 33 · VulnSea