VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

876 CVEsRSS

CVE-2026-55479None
2mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the checkin permission, allowing a user who can assign licenses …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-55475Medium· 5.7
2mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the created_by value of an import file, allowing unauthorized modifi…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-55462Medium· 4.3
2mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned license, accessory, and consumable relationships, allowing …

▾ SunlitEPSS 0.34%via NVD
CVE-2026-59154Medium· 4.3
2mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct Meteor collection allow rules for Checklists and ChecklistItems because updates are authorized only against the curr…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-15318Medium· 6.3
2mo ago

A weakness has been identified in Sipeed PicoClaw up to 0.2.9

A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqtt.go of the component MQTT Channel Handler. This manipulation of the argument client_id …

▾ SunlitEPSS 0.37%via NVD
CVE-2026-58254Medium· 6.5
2mo ago

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were applied to ordinary client connections but not consistently to messages a…

▾ Sunlitlinuxfoundation · nats-serverEPSS 0.31%via NVD
CVE-2026-35211Medium· 6.5
2mo ago

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exposes a script filter operator in its FilterOperator enum that allows any authenticated u…

▾ Sunlitciteum · openctiEPSS 0.52%via NVD
CVE-2026-35210High· 7.1
2mo ago

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0, an authorization bypass vulnerability in OpenCTI allows any authenticated user with KNOWLEDGE_KNUPDATE permission t…

▾ Twilightciteum · openctiEPSS 0.35%via NVD
CVE-2026-58214Medium· 4.3
2mo ago

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject family, bypassing co…

▾ Sunlitlinuxfoundation · nats-serverEPSS 0.35%via NVD
CVE-2026-58209Medium· 4.3
2mo ago

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a…

▾ Sunlitlinuxfoundation · nats-serverEPSS 0.34%via NVD
CVE-2026-12352Medium· 5.9PoC
2mo ago

This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.

This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.

▾ TwilightEPSS 0.40%via NVD
GHSA-f66q-9rf6-8795Medium
2mo ago

Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion

Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion

▾ Sunlitflask-security-too · flask-security-toovia OSV
GHSA-p2fr-6hmx-4528Medium· 6.4
2mo ago

@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators

@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators

▾ Sunlitbetter-auth · @better-auth/oauth-providervia GHSA
CVE-2026-53512Critical· 9.1
2mo ago

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

▾ Midnightbetter-auth · better-authEPSS 0.27%via GHSA
GHSA-qrwj-vh9x-gw5vHigh· 8.3
2mo ago

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

▾ Twilightcoder · github.com/coder/coder/v2via GHSA
CVE-2026-55428High· 8.2
2mo ago

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.40%via GHSA
CVE-2026-55435Medium· 5.4
2mo ago

Suspended Coder users retain access to AI Bridge LLM proxy endpoints

Suspended Coder users retain access to AI Bridge LLM proxy endpoints

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.32%via GHSA
CVE-2026-35370Medium· 4.4
2mo ago

id: groups= computed from real GID instead of effective GID

id: groups= computed from real GID instead of effective GID

▾ Sunlituu_id · uu_idEPSS 0.13%via GHSA
CVE-2026-28740High· 7.1
2mo ago

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.

▾ TwilightEPSS 0.32%via NVD
CVE-2026-27780None
2mo ago

Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.

Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.

▾ SunlitEPSS 0.64%via NVD
CVE-2026-27775None
2mo ago

Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.

Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.

▾ SunlitEPSS 0.52%via NVD
CVE-2026-27761Medium· 4.3
2mo ago

Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.

Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.

▾ SunlitEPSS 0.37%via NVD
CVE-2026-46730Medium· 4.2
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect aut…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect aut…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-54998High· 8.8PoC
2mo ago

Microsoft Exchange Online Elevation of Privilege Vulnerability

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Exchange OnlineEPSS 0.78%via CVEORG
CVE-2026-9808High· 7.1
2mo ago

Mautic has an Authorization Bypass in API v2 Endpoints

Mautic has an Authorization Bypass in API v2 Endpoints

▾ Twilightmautic · mautic/coreEPSS 0.34%via GHSA
GHSA-qjpc-qf9m-xwmrHigh· 8.8
2mo ago

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing

▾ Twilightopenclaw · openclawvia GHSA
GHSA-w4v6-g3wm-w36cCritical
2mo ago

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy

▾ Midnightopenclaw · openclawvia GHSA
GHSA-xr4f-mjxj-w6w5High· 8.3
2mo ago

OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes

OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes

▾ Twilightopenclaw · openclawvia GHSA
GHSA-77pv-3w4q-vrj5Medium
2mo ago

OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks

OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks

▾ Sunlitopenclaw · openclawvia GHSA
CVE-2026-53809Medium· 3.8
2mo ago

OpenClaw: Embedded runner policy could be confused by provider aliases

OpenClaw: Embedded runner policy could be confused by provider aliases

▾ Sunlitopenclaw · openclawEPSS 0.13%via GHSA
CWE-863 vulnerabilities (CVEs) — page 23 · VulnSea