VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

874 CVEsRSS

CVE-2026-18690High· 8.1
1mo ago

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical sy…

▾ Twilightmongodb · mongodbEPSS 0.41%via NVD
CVE-2026-69278High· 7.8
1mo ago

Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

▾ Twilightmicrosoft · visual_studio_codeEPSS 0.32%via NVD
CVE-2026-18635High· 7.2
1mo ago

Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context

Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administ…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-18348Medium· 4.1
1mo ago

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the …

Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the …

▾ SunlitEPSS 0.34%via NVD
CVE-2026-61925High· 7.8
1mo ago

Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.30%via NVD
CVE-2026-69118High· 8.8
1mo ago

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attackers can create malicious incident templates with Blade direc…

▾ TwilightEPSS 0.80%via NVD
CVE-2026-72886Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the…

▾ MidnightEPSS 0.52%via NVD
CVE-2026-19350Medium· 6.3
1mo ago

A vulnerability has been found in Dolibarr ERP up to 23.0.3

A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be perfor…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-19345Medium· 6.5
1mo ago

A vulnerability was found in code-projects Task Management System 1.0

A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to …

▾ SunlitEPSS 0.55%via NVD
CVE-2026-17594Medium· 4.9PoC
1mo ago

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scope…

▾ Twilightsonatype · nexus_repository_managerEPSS 0.74%via NVD
CVE-2026-37171Medium· 5.9PoC
1mo ago

A lack of tenant separation in SuperTokens Inc

A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.

▾ TwilightEPSS 0.31%via NVD
CVE-2026-66000None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing users whose access was revoked or reduce…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-45808High
1mo ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying cred…

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.43%via NVD
CVE-2026-66059None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.

▾ SunlitEPSS 0.48%via NVD
CVE-2026-52466Critical· 9.8
1mo ago

Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control

Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that …

▾ MidnightEPSS 0.48%via NVD
CVE-2026-48076Medium· 6.5
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` (returns a 16-bit PoW chal…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-48074Low· 2.7
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying `StaffService.deleteStaffMember()` run…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-47185None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authenticated user without enforcing workspace ownership, allowing modification of another user…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-7867High· 7.8PoC
1mo ago

A flaw was found in udisks2

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker…

▾ MidnightRed Hat · udisksEPSS 0.17%via NVD
GHSA-xxpx-f366-4xpqMedium
1mo ago

Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element

Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element

▾ Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-71433Medium· 5.3
1mo ago

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarc…

▾ Sunlitlanggraph-checkpoint-postgres · langgraph-checkpoint-postgresEPSS 0.36%via NVD
CVE-2026-71325Medium· 4.4⚖ disputed
1mo ago

Traefik is an open-source edge router that makes publishing services a fun and easy experience

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolv…

▾ Sunlittraefik · traefikEPSS 0.15%via NVD
CVE-2026-54765Medium
1mo ago

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

▾ Sunlittraefik · github.com/traefik/traefik/v3EPSS 0.35%via GHSA
CVE-2026-45414High· 8.5
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be …

▾ Twilightdecidim · decidimEPSS 0.45%via NVD
CVE-2026-71201Medium· 5.0
1mo ago

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.

▾ SunlitEPSS 0.28%via NVD
CVE-2026-71192None
1mo ago

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT reque…

▾ SunlitEPSS 0.44%via NVD
CVE-2026-71191None
1mo ago

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Cop…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-71234High· 7.5
1mo ago

Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (l…

Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (l…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-65602Medium
1mo ago

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

▾ Sunlittraefik · github.com/traefik/traefik/v3EPSS 0.33%via GHSA
CVE-2026-71315High· 8.2
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorizatio…

▾ Twilightnuxt · nuxtEPSS 0.47%via NVD
CWE-863 vulnerabilities (CVEs) — page 18 · VulnSea