VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2026-48500Medium· 6.5
3mo ago

Filament: Unauthenticated temporary file upload on auth pages

Filament: Unauthenticated temporary file upload on auth pages

▾ Sunlitfilament · filament/filamentEPSS 0.34%via GHSA
CVE-2026-49205Medium· 6.5
3mo ago

phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)

phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)

▾ Sunlitthorsten · thorsten/phpmyfaqEPSS 0.39%via GHSA
CVE-2026-55542Low
3mo ago

Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL

Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.28%via GHSA
CVE-2026-56104High· 7.4
3mo ago

Chainlit contains a session hijacking vulnerability

Chainlit contains a session hijacking vulnerability

▾ Twilightchainlit · chainlitEPSS 0.42%via OSV
CVE-2026-5139Medium· 5.4
3mo ago

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

▾ Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.29%via OSV
CVE-2026-44914High· 7.2
3mo ago

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additio…

▾ Twilightapache · nifiEPSS 0.66%via NVD
CVE-2026-33684Medium· 5.3
3mo ago

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

▾ Sunlitwwbn · wwbn/avideoEPSS 0.33%via GHSA
CVE-2026-44585Medium· 5.4
3mo ago

Paymenter has broken object level authorization via service reference manipulation on ticket creation

Paymenter has broken object level authorization via service reference manipulation on ticket creation

▾ Sunlitpaymenter · paymenter/paymenterEPSS 0.29%via GHSA
CVE-2026-50137High
3mo ago

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

▾ Twilightbudibase · @budibase/serverEPSS 0.41%via GHSA
CVE-2026-52799High· 7.5
3mo ago

Gogs Missing Authorization in Attachment Download

Gogs Missing Authorization in Attachment Download

▾ Twilightgogs · gogs.io/gogsEPSS 0.42%via GHSA
GHSA-rg7q-4223-phjwHigh· 7.5
3mo ago

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

▾ Twilightwwbn · wwbn/avideovia GHSA
CVE-2026-48582Critical· 9.6
3mo ago

Microsoft Exchange Online Elevation of Privilege Vulnerability

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.69%via CVEORG
CVE-2026-55414Medium· 5.3
3mo ago

NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)

NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)

▾ Sunlitnl-portal · nl.nl-portal:formvia GHSA
GHSA-c8qj-jx8j-fg2wCritical
3mo ago

DotVVM: Missing authorization in AuthorizeActionFilter

DotVVM: Missing authorization in AuthorizeActionFilter

▾ MidnightDotVVM · DotVVMvia GHSA
GHSA-mqq5-j7w8-2hghHigh· 7.5
3mo ago

AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content

AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content

▾ Twilightalchemy_cms · alchemy_cmsvia GHSA
GHSA-mxjx-28vx-xjjjMedium· 5.9
3mo ago

Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions

Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions

▾ Sunlitnetwork-ai · network-aivia GHSA
GHSA-vmf9-xx9w-86wxHigh· 8.3
3mo ago

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

▾ Twilightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-5qw8-f2g9-ff29High· 8.2
3mo ago

PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard

PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-qvpf-j64c-jmhrHigh· 8.3
3mo ago

PraisonAI Slack app_mention bypasses configured user/channel authorization

PraisonAI Slack app_mention bypasses configured user/channel authorization

▾ Twilightpraisonai · praisonaivia GHSA
CVE-2026-11719High
3mo ago

MCP Toolbox for Databases: authenticated authorization bypass

MCP Toolbox for Databases: authenticated authorization bypass

▾ Twilightgoogleapis · github.com/googleapis/mcp-toolboxEPSS 0.14%via GHSA
GHSA-fq2m-6wqh-x44gCritical· 9.8
3mo ago

PraisonAI: Jobs API exposes agent-execution endpoints with no authentication

PraisonAI: Jobs API exposes agent-execution endpoints with no authentication

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-x8cv-xmq7-p8xpCritical· 9.8
3mo ago

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

▾ Midnightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-892r-p3jq-jp24Critical· 9.8
3mo ago

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-j4f3-55x4-r6q2Critical· 9.8
3mo ago

npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call

npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-h2w2-v7j6-xqm4High· 8.8
3mo ago

npm PraisonAI AgentLoop onToolCall approval runs after tool execution

npm PraisonAI AgentLoop onToolCall approval runs after tool execution

▾ Twilightpraisonai · praisonaivia GHSA
CVE-2026-49274Medium
3mo ago

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.48%via GHSA
CVE-2026-54004Medium
3mo ago

Kirby: Access to files of top-level drafts is not protected by permissions

Kirby: Access to files of top-level drafts is not protected by permissions

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.50%via GHSA
CVE-2026-54005High
3mo ago

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

▾ Twilightgetkirby · getkirby/cmsEPSS 0.43%via GHSA
CVE-2026-54695High· 7.5
3mo ago

Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID

Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID

▾ Twilightpipecat-ai · pipecat-aiEPSS 0.56%via GHSA
GHSA-hjwc-26pj-v3pmHigh
3mo ago

AgenticMail: Cross-agent task authorization bypass in AgenticMail API

AgenticMail: Cross-agent task authorization bypass in AgenticMail API

▾ Twilightagenticmail · @agenticmail/apivia GHSA
CWE-862 vulnerabilities (CVEs) — page 39 · VulnSea