VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

GHSA-vjc7-jrh9-9j86Critical· 10.0
2mo ago

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

▾ Midnight9router · 9routervia GHSA
GHSA-x76w-8c62-48mgMedium
2mo ago

Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission

Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-49445Critical· 9.2
2mo ago

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access

▾ Midnightcilium · github.com/cilium/ciliumEPSS 0.17%via GHSA
CVE-2026-27771High· 8.2PoC
2mo ago

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

▾ MidnightEPSS 1.4%via NVD
CVE-2026-25038None
2mo ago

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

▾ SunlitEPSS 0.48%via NVD
CVE-2026-14460High· 8.8
2mo ago

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from <= 1.0.4 before 1.0.5.

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from <= 1.0.4 before 1.0.5.

▾ TwilightEPSS 0.16%via NVD
CVE-2026-11398Medium· 5.3
2mo ago

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.6.1

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is a…

▾ SunlitEPSS 0.56%via NVD
CVE-2026-9230Medium· 4.3
2mo ago

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that a user is author…

▾ SunlitEPSS 0.49%via NVD
CVE-2026-12557Medium· 5.3
2mo ago

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-59800Critical
2mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routerEPSS 2.0%via GHSA
GHSA-j5mc-p8qg-39j7Low
2mo ago

Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation

Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation

▾ Sunlitkimai · kimai/kimaivia GHSA
CVE-2026-50282High
2mo ago

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

▾ Twilightcraftcms · craftcms/cmsEPSS 0.35%via GHSA
GHSA-g6g7-pvmx-m74pCritical
2mo ago

9router: Missing Authorization and OS Command Injection

9router: Missing Authorization and OS Command Injection

▾ Midnight9router · 9routervia GHSA
CVE-2026-50284High
2mo ago

Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets

Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets

▾ Twilightcraftcms · craftcms/cmsEPSS 0.39%via GHSA
GHSA-f9ff-5x35-7gfwHigh
2mo ago

Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)

Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)

▾ Twilightgrackle-ai · @grackle-ai/mcpvia GHSA
GHSA-qjpc-qf9m-xwmrHigh· 8.8
2mo ago

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

▾ Twilightopenclaw · openclawvia GHSA
GHSA-hcm3-8f6r-6xwgMedium· 6.5
2mo ago

OpenClaw: Browser debug/export routes could reuse already-open blocked tabs

OpenClaw: Browser debug/export routes could reuse already-open blocked tabs

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-3wqp-prf6-2m72Low· 3.1
2mo ago

OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement

OpenClaw: Feishu dynamic-agent bindings could miss configWrites enforcement

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-53818Medium· 6.6
2mo ago

OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers

OpenClaw: MCP loopback could skip owner-only tool policy for non-owner callers

▾ Sunlitopenclaw · openclawEPSS 0.14%via GHSA
CVE-2026-53816High· 7.2
2mo ago

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

▾ Twilightopenclaw · openclawEPSS 0.50%via GHSA
CVE-2026-53815High· 6.5
2mo ago

OpenClaw: Message read actions could skip channel allowlist checks

OpenClaw: Message read actions could skip channel allowlist checks

▾ Twilightopenclaw · openclawEPSS 0.36%via GHSA
GHSA-mgq6-vr84-7m2jHigh· 8.0
2mo ago

OpenClaw: QQBot native approval buttons did not enforce configured approver identity

OpenClaw: QQBot native approval buttons did not enforce configured approver identity

▾ Twilightopenclaw · openclawvia GHSA
GHSA-hw9r-h9mr-4jffHigh· 8.8
2mo ago

OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates

OpenClaw: Scoped chat.send route inheritance could bypass admin command scope gates

▾ Twilightopenclaw · openclawvia GHSA
GHSA-wp87-mgvq-5j93Medium· 6.5
2mo ago

SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization

SurrealDB: USE NS/DB implicit creation bypasses DEFINE authorization

▾ Sunlitsurrealdb · surrealdbvia GHSA
GHSA-gcwr-5mrf-fvchMedium· 5.4
2mo ago

SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries

SurrealDB: Authorization Bypass in KILL Statement Allows Termination of Other Users' Live Queries

▾ Sunlitsurrealdb · surrealdbvia GHSA
CVE-2026-46487High· 7.5
2mo ago

GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field

GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field

▾ Twilightgeonetwork-opensource · org.geonetwork-opensource:geonetworkvia GHSA
CVE-2026-58373Medium· 4.3
3mo ago

CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing…

CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifiers belonging to other organizations by exploiting a missing…

▾ Sunlitcvat · computer_vision_annotation_toolEPSS 0.34%via NVD
CVE-2026-49821High· 7.7
3mo ago

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

▾ Twilightfission · github.com/fission/fissionEPSS 0.40%via GHSA
CVE-2026-49822High· 7.7
3mo ago

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance

▾ Twilightfission · github.com/fission/fissionEPSS 0.40%via GHSA
CVE-2026-48592Medium
3mo ago

oban_web missing authorization check on `save-job` event handler

oban_web missing authorization check on `save-job` event handler

▾ Sunlitoban_web · oban_webEPSS 0.56%via GHSA
CWE-862 vulnerabilities (CVEs) — page 37 · VulnSea