VulnSea

CWE-862

CVEs classified under CWE-862, newest first.

1328 CVEsRSS

CVE-2026-63116High· 8.8PoC
6d ago

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From 10.1.0 until 10.1.1, src/services/permission/valve/rules-map.ts omits RECORD_ACTION.PATCH_MULTI from RULES_MAP. When…

▾ MidnightdeepstreamIO · deepstream.ioEPSS 0.51%via NVD
CVE-2026-83621High· 8.1
6d ago

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.…

▾ Twilightntop · ntopngEPSS 0.53%via NVD
CVE-2026-84990High· 8.8
6d ago

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any a…

▾ Twilightntop · ntopngEPSS 0.46%via NVD
CVE-2026-79920Critical· 9.9
6d ago

Ajenti is a Linux & BSD modular server admin panel

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-mana…

▾ Midnightajenti · ajentiEPSS 0.62%via NVD
CVE-2026-84298Low· 3.1
6d ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map …

▾ Sunlithatchet-dev · hatchetEPSS 0.24%via NVD
CVE-2026-94394Medium· 6.3
6d ago

When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of…

When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of…

▾ SunlitMISP · MISPEPSS 0.35%via NVD
CVE-2026-86802Low· 3.7
6d ago

The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary…

The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-94218Low· 3.1
6d ago

A flaw was found in the authentication session management of Keycloak, an identity and access management solution

A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authenticatio…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.31%via NVD
CVE-2026-94217Low· 3.5
6d ago

A flaw was found in the User-Managed Access (UMA) implementation of Keycloak

A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system in…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.24%via NVD
CVE-2026-94213Medium· 4.9
6d ago

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.39%via NVD
CVE-2026-94215Medium· 5.5
6d ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifyi…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.30%via NVD
CVE-2026-94113Medium· 6.5
1w ago

Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions

Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated attackers can call get_projectwise…

▾ SunlitFrappe · ERPNextEPSS 0.42%via NVD
CVE-2026-92965Low· 3.7
1w ago

The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, …

The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, …

▾ SunlitEPSS 0.24%via NVD
CVE-2026-94000Medium· 6.6
1w ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges be…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.40%via NVD
CVE-2026-93999Medium· 4.2
1w ago

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client I…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.23%via NVD
CVE-2026-94001Medium· 6.5
1w ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.44%via NVD
CVE-2026-18346Medium· 5.3
1w ago

The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1

The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible fo…

▾ Sunlittiktokbusinessplugin · TikTokEPSS 0.26%via NVD
CVE-2026-9858Medium· 4.3
1w ago

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions. This is d…

▾ Sunlitwpexpertshub · Partial Shipment for WooCommerceEPSS 0.35%via NVD
CVE-2026-9766Medium· 4.3
1w ago

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

▾ Sunlitempik · Empik for WoocommerceEPSS 0.40%via NVD
CVE-2026-9613Medium· 4.3
1w ago

The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65

The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform…

▾ Sunlitdatalogics · Datalogics Ecommerce Delivery – DatalogicsEPSS 0.60%via NVD
CVE-2026-9615Medium· 4.3
1w ago

The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0

The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() and license_deactivate_fleximp() functions, hooked to the wp_ajax_licens…

▾ Sunlitflextheme · Flex ImportEPSS 0.43%via NVD
CVE-2026-15947Medium· 4.3
1w ago

The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_instant_indexing_settings() function in versions up to, and including, 2.6.23

The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_instant_indexing_settings() function in versions up to, and including, 2.6.23. This function is registered…

▾ Sunlitshahrukhlinkgraph · Search Atlas SEO – OTTO AI SEO Automation for WordPressEPSS 0.21%via NVD
CVE-2026-4792Medium· 5.3
1w ago

The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12

The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due to the lack of authentication and authorization checks on the settings export functionality (download_settings funct…

▾ Sunlitradius314 · BreadEPSS 0.58%via NVD
CVE-2026-2278Medium· 4.3
1w ago

The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8

The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it po…

▾ Sunlitvowelweb · VW Writer BlogEPSS 0.20%via NVD
CVE-2026-11899Medium· 4.3
1w ago

The PDF Builder for WooCommerce

The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.11. This is due to the plugin not properly verifying that a user…

▾ Sunlitedgarrojas · PDF Builder for WooCommerce. Create invoices,packing slips and moreEPSS 0.21%via NVD
CVE-2026-9232Medium· 6.5
1w ago

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-…

▾ Sunliteasyappointments · Easy AppointmentsEPSS 0.47%via NVD
CVE-2026-15946Medium· 4.3
1w ago

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.23. This is due to the plugin not pro…

▾ Sunlitshahrukhlinkgraph · Search Atlas SEO – OTTO AI SEO Automation for WordPressEPSS 0.23%via NVD
CVE-2026-1984Medium· 5.3
1w ago

The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7

The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This…

▾ Sunlitvowelweb · Ibtana – Ecommerce Product AddonsEPSS 0.23%via NVD
CVE-2026-85574High· 8.0
1w ago

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy a…

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy a…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-86591Critical· 9.8
1w ago

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege e…

The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege e…

▾ MidnightEPSS 0.54%via NVD
CWE-862 vulnerabilities (CVEs) — page 7 · VulnSea