VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

876 CVEsRSS

CVE-2026-1752Medium· 4.3
5mo ago

GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected en…

GitLab has remediated an issue in GitLab EE affecting all versions from 11.3 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user with developer-role permissions to modify protected en…

▾ Sunlitgitlab · gitlabEPSS 0.31%via NVD
CVE-2026-27140High· 8.8
5mo ago

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

▾ Twilightgolang · goEPSS 0.81%via NVD
CVE-2026-28808Critical· 9.8⚖ disputed
5mo ago

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside Docum…

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside Docum…

▾ Midnighterlang · erlang/inetsEPSS 0.77%via NVD
CVE-2026-27447Medium· 4.8
5mo ago

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username compar…

▾ Sunlitopenprinting · cupsEPSS 0.26%via NVD
CVE-2026-34453High· 7.5PoC
6mo ago

SiYuan is a personal knowledge management system

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks from password-protected documents to unauthenticated visitors. In publish/read-only mode, /api/bookmark/getBookmark f…

▾ Midnightb3log · siyuanEPSS 1.5%via NVD
CVE-2026-24029Medium· 6.5
6mo ago

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configure…

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configure…

▾ Sunlitpowerdns · dnsdistEPSS 0.15%via NVD
CVE-2026-34506Medium· 4.3
6mo ago

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an e…

▾ Sunlitopenclaw · openclawEPSS 0.34%via NVD
CVE-2026-33579Critical· 9.9PoC
6mo ago

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check

OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can…

▾ Abyssalopenclaw · openclawEPSS 0.51%via NVD
CVE-2026-33578Medium· 4.3
6mo ago

OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy

OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where route-level group allowlist policies silently downgrade to open policy. Attackers can exploit this policy resolution…

▾ Sunlitopenclaw · openclawEPSS 0.31%via NVD
CVE-2026-33577High· 8.1
6mo ago

OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes

OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes. Attackers can exploit missing callerScopes vali…

▾ Twilightopenclaw · openclawEPSS 0.42%via NVD
CVE-2026-33576Medium· 6.5
6mo ago

OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization

OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. Unauthorized senders can force network fetches and disk writes to the media store by sending messages that are subseq…

▾ Sunlitopenclaw · openclawEPSS 0.43%via NVD
CVE-2026-34532Critical· 9.1
6mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.…

▾ Midnightparseplatform · parse-serverEPSS 0.49%via NVD
CVE-2026-30689Medium· 4.3
6mo ago

In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure

In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threate…

▾ Sunlitanjoy8 · blog.adminEPSS 0.33%via NVD
CVE-2026-33217High· 7.1
6mo ago

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing M…

▾ Twilightlinuxfoundation · nats-serverEPSS 0.37%via NVD
CVE-2025-69196Medium· 6.5
6mo ago

FastMCP is the standard framework for building MCP applications

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the …

▾ Sunlitjlowin · fastmcpEPSS 0.36%via NVD
CVE-2026-32597High· 7.5PoC
6mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not …

▾ Midnightpyjwt_project · pyjwtEPSS 0.28%via NVD
CVE-2026-31887High
6mo ago

Shopware: Unauthenticated data extraction possible through store-api.order endpoint

Shopware: Unauthenticated data extraction possible through store-api.order endpoint

▾ Twilightshopware · shopware/coreEPSS 0.39%via GHSA
CVE-2026-1524Critical· 9.8
6mo ago

An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin configures two or more OIDC providers AND configures one o…

An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin configures two or more OIDC providers AND configures one o…

▾ Midnightneo4j · neo4jEPSS 0.32%via NVD
CVE-2026-1497High· 7.2
6mo ago

Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:  an admin that intends to give a user an access to a remote database constitue…

Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:  an admin that intends to give a user an access to a remote database constitue…

▾ Twilightneo4j · neo4jEPSS 0.24%via NVD
CVE-2026-28474Critical· 9.8
6mo ago

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists

OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their…

▾ Midnightopenclaw · openclawEPSS 0.84%via NVD
CVE-2026-3009High· 8.1
6mo ago

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can…

▾ Twilightredhat · build_of_keycloakEPSS 0.47%via NVD
CVE-2026-21721High· 8.1PoC
8mo ago

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on ot…

▾ Midnightgrafana · grafanaEPSS 0.73%via NVD
CVE-2026-22822High· 8.8
8mo ago

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introd…

▾ Twilightexternal-secrets · external_secrets_operatorEPSS 0.19%via NVD
CVE-2026-21274High· 7.8
8mo ago

Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user

Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to byp…

▾ Twilightadobe · dreamweaverEPSS 0.24%via NVD
CVE-2025-34467Medium· 4.3
9mo ago

ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management

ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management. When an authenticated low-privilege use…

▾ Sunlitzwiicms · zwiicmsEPSS 0.22%via NVD
CVE-2025-2515High· 7.2
9mo ago

A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS

A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node.…

▾ TwilightEPSS 0.21%via NVD
CVE-2025-68476None
9mo ago

KEDA is a Kubernetes-based Event Driven Autoscaling component

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication…

▾ SunlitEPSS 0.55%via NVD
CVE-2025-67490Medium· 5.4
9mo ago

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRe…

▾ Sunlitauth0 · nextjs-auth0EPSS 0.20%via NVD
CVE-2025-13184Critical· 9.8
9mo ago

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution)

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the sam…

▾ Midnighttotolink · x5000r_firmwareEPSS 11%via NVD
CVE-2025-8148Medium· 4.2
9mo ago

An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their…

An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their…

▾ Sunlitfortra · goanywhere_managed_file_transferEPSS 0.17%via NVD
CWE-863 vulnerabilities (CVEs) — page 28 · VulnSea