VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

756 CVEsRSS

CVE-2026-92893Medium· 4.3
4d ago

A flaw was found in the foreman_ansible plugin's Ansible inventory API

A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An…

SunlitRed Hat · rubygem-foreman_ansibleEPSS 0.28%via NVD
CVE-2026-81439Low· 3.7
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechani…

SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.19%via NVD
CVE-2026-78426Low· 3.7
4d ago

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equ…

Sunlitgo · neuvectorEPSS 0.12%via NVD
CVE-2026-92894Medium· 4.3
4d ago

A flaw was found in the foreman_ansible plugin's Ansible override values API

A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authent…

SunlitRed Hat · rubygem-foreman_ansibleEPSS 0.26%via NVD
CVE-2026-90923Medium· 6.5
4d ago

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.

SunlitEPSS 0.16%via NVD
CVE-2026-92760Medium· 6.5PoC
5d ago

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the mercure-info end…

Twilightshlinkio · shlinkEPSS 0.40%via NVD
CVE-2026-92764Medium· 4.3
5d ago

OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships

OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organizatio…

Sunlitopencve · opencveEPSS 0.30%via NVD
CVE-2026-92771Medium· 6.5PoC
5d ago

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue…

Twilighttwentyhq · twentyEPSS 0.32%via NVD
CVE-2026-92774Medium· 4.3PoC
5d ago

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve…

Twilightrequarks · Wiki.jsEPSS 0.35%via NVD
CVE-2026-92776High· 8.1PoC
5d ago

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated …

Midnightrequarks · Wiki.jsEPSS 0.25%via NVD
CVE-2026-92782High· 8.1PoC
5d ago

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, a…

Midnightchroma-core · chromaEPSS 0.25%via NVD
CVE-2026-92788High· 8.8
5d ago

Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace

Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable table identifiers and execute SQL statements against oth…

Twilightcoze-dev · coze-studioEPSS 0.28%via NVD
CVE-2026-92793High· 8.1
5d ago

GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter

GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the adm…

TwilightGoAdminGroup · go-adminEPSS 0.25%via NVD
CVE-2026-92801High· 8.8
5d ago

cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks

cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the p…

Twilightchenhg5 · cc-connectEPSS 0.30%via NVD
CVE-2026-92796High· 8.8PoC
5d ago

Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries

Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements a…

Midnightmanticoresoftware · Manticore SearchEPSS 0.28%via NVD
CVE-2026-86043High· 7.5PoC
5d ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent beca…

Midnightzalando · skipperEPSS 0.50%via NVD
CVE-2026-92402Medium· 6.3
5d ago

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component top.upstudy.crm.controller.UserController. The …

SunlitChangeWeDer · crmEPSS 0.35%via NVD
CVE-2026-20072Medium· 4.9
5d ago

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to. &nb…

SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.37%via NVD
CVE-2026-76438Medium· 6.5
5d ago

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerabili…

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerabili…

SunlitCisco · Cisco BroadWorksEPSS 0.33%via NVD
CVE-2026-61709Medium· 5.3
5d ago

OpenFGA is an authorization and permission engine built for developers

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not e…

Sunlitopenfga · openfgaEPSS 0.34%via NVD
CVE-2026-92130Low· 3.1
5d ago

Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture cred…

Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture cred…

SunlitJenkins Project · Jenkins Pipeline: Multibranch PluginEPSS 0.21%via NVD
CVE-2026-73469Medium· 5.8
5d ago

When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop

When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on…

SunlitArista Networks · EOSEPSS 0.29%via NVD
CVE-2026-19640Medium· 4.2
5d ago

On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissi…

On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissi…

SunlitArista Networks · EOSEPSS 0.19%via NVD
CVE-2026-27552High· 8.1
5d ago

A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.

A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.

TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.56%via NVD
CVE-2026-79708High· 8.5
5d ago

GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to …

GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to …

TwilightGitLab · GitLabEPSS 0.34%via NVD
CVE-2026-73460Medium· 6.1
5d ago

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may r…

SunlitArista Networks · EOSEPSS 0.18%via NVD
CVE-2026-76863Medium· 4.3
6d ago

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can access th…

SunlitNetcore · NR255-VEPSS 0.22%via NVD
GHSA-5648-rgj9-v224High· 8.1
6d ago

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

Twilightzereight · @zereight/mcp-gitlabvia GHSA
CVE-2026-91735High· 8.3
6d ago

Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secu…

Twilightgoogle · chromeEPSS 0.31%via NVD
CVE-2026-91734High· 7.4
6d ago

Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program

Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.10%via NVD
CWE-863 vulnerabilities (CVEs) — page 2 · VulnSea