VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1332 CVEsRSS

CVE-2026-53844Medium· 6.5
3mo ago

OpenClaw: memory-wiki shared search could miss session visibility checks

OpenClaw: memory-wiki shared search could miss session visibility checks

▾ Sunlitopenclaw · openclawEPSS 0.36%via GHSA
CVE-2026-53850Medium
3mo ago

OpenClaw: Focus command could miss controlScope enforcement

OpenClaw: Focus command could miss controlScope enforcement

▾ Sunlitopenclaw · openclawEPSS 0.14%via GHSA
CVE-2026-54415High· 8.1PoC
3mo ago

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over…

▾ MidnightEPSS 0.49%via NVD
CVE-2026-54010High· 8.3
3mo ago

Open WebUI: Forged chat-file link allows cross-user file read and deletion

Open WebUI: Forged chat-file link allows cross-user file read and deletion

▾ Twilightopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-54012High· 7.1
3mo ago

Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion

Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion

▾ Twilightopen-webui · open-webuiEPSS 0.33%via GHSA
CVE-2026-54016Medium· 4.3
3mo ago

Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration

Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration

▾ Sunlitopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-54019Medium· 6.5
3mo ago

Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode

Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode

▾ Sunlitopen-webui · open-webuiEPSS 0.39%via GHSA
CVE-2026-12515Medium· 4.3
3mo ago

katello: missing repository authorization in content_uploads exposes cross-product content existence

katello: missing repository authorization in content_uploads exposes cross-product content existence

▾ Sunlitkatello · katelloEPSS 0.22%via GHSA
CVE-2026-55518Critical· 9.6
3mo ago

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation

▾ Midnightavo · avoEPSS 0.45%via GHSA
CVE-2026-0158Medium· 4.0
3mo ago

In Camera, there is a possible unauthorized way to access photos due to a missing permission check

In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi…

▾ Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-0145Medium· 4.0
3mo ago

In keymint, there is a possible Permission Bypass due to a logic error in the code

In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

▾ Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-54322High· 7.7
3mo ago

Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles

Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles

▾ Twilightdaytonaio · github.com/daytonaio/daytonaEPSS 0.30%via GHSA
GHSA-6jm4-83g2-35gvMedium· 6.5
3mo ago

Duplicate Advisory: memory-wiki shared search could miss session visibility checks

Duplicate Advisory: memory-wiki shared search could miss session visibility checks

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-gw2c-6hcg-5g52Medium· 5.5
3mo ago

Duplicate Advisory: Focus command could miss controlScope enforcement

Duplicate Advisory: Focus command could miss controlScope enforcement

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-c8w7-9w9h-x69qMedium· 5.3
3mo ago

Duplicate Advisory: Slack reaction events could ignore reaction notification settings

Duplicate Advisory: Slack reaction events could ignore reaction notification settings

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-v383-2wgg-v483High· 8.1
3mo ago

Duplicate Advisory: Shell inline-command parsing could miss an allowlist check

Duplicate Advisory: Shell inline-command parsing could miss an allowlist check

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-25714Medium· 4.3
3mo ago

Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw

Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
CVE-2026-27783Medium· 4.3
3mo ago

Gitea: Missing repository-unit authorization on issue-template API endpoints

Gitea: Missing repository-unit authorization on issue-template API endpoints

▾ Sunlitgitea · code.gitea.io/giteaEPSS 0.34%via GHSA
GHSA-wqvq-jvpq-h66fMedium· 5.4
3mo ago

Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization

Nodemailer jsonTransport bypasses disableFileAccess and disableUrlAccess during message normalization

▾ Sunlitnodemailer · nodemailervia GHSA
CVE-2026-53633Critical· 9.8
3mo ago

Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE

Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE

▾ Midnightvitest · @vitest/browserEPSS 0.90%via GHSA
CVE-2026-48151High· 7.5
3mo ago

Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema

Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema

▾ Twilightbudibase · @budibase/serverEPSS 0.38%via GHSA
CVE-2026-47351Medium
3mo ago

TYPO3 CMS: Broken Access Control in Media Module

TYPO3 CMS: Broken Access Control in Media Module

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-47352Medium
3mo ago

TYPO3 CMS has Broken Access Control in Backend API

TYPO3 CMS has Broken Access Control in Backend API

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-47346High
3mo ago

TYPO3 CMS has Broken Access Control in its Form Framework

TYPO3 CMS has Broken Access Control in its Form Framework

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.44%via GHSA
CVE-2026-47350Medium
3mo ago

TYPO3 CMS has Broken Access Control in its DataHandler

TYPO3 CMS has Broken Access Control in its DataHandler

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-49741High
3mo ago

TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework

TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.37%via GHSA
CVE-2026-47343High
3mo ago

TYPO3 CMS: Destructive Actions on File Mount Folders

TYPO3 CMS: Destructive Actions on File Mount Folders

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-47349Medium
3mo ago

TYPO3 CMS has Broken Access Control in the Recycler Module

TYPO3 CMS has Broken Access Control in the Recycler Module

▾ Sunlittypo3 · typo3/cms-coreEPSS 0.41%via GHSA
CVE-2026-11607High
3mo ago

TYPO3 CMS has Broken Access Control in its Form Framework

TYPO3 CMS has Broken Access Control in its Form Framework

▾ Twilighttypo3 · typo3/cms-coreEPSS 0.24%via GHSA
CVE-2023-32959Medium· 4.3
3mo ago

Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2.

Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MetroStore: from n/a through 1.3.2.

▾ SunlitEPSS 0.18%via NVD
CWE-862 vulnerabilities (CVEs) — page 40 · VulnSea