VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

876 CVEsRSS

CVE-2025-66623High· 7.4
9mo ago

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.1, in some situations, Strimzi creates an incorrect Kubernetes Role which grants the Apa…

▾ Twilightlinuxfoundation · strimziEPSS 0.17%via NVD
CVE-2025-66581Medium· 6.5
9mo ago

Frappe Learning Management System (LMS) is a learning system that helps users structure their content

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side authorization logic allowed authenticated users to perform actions beyond their assigned ro…

▾ Sunlitfrappe · learningEPSS 0.21%via NVD
CVE-2024-32643High· 7.5
9mo ago

Masa CMS is an open source Enterprise Content Management platform

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a /tag/ declaration, the CMS will render the page regardless of group restrictions. This …

▾ Twilightmasacms · masacmsEPSS 0.36%via NVD
CVE-2025-13806High· 7.3
10mo ago

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthMo…

▾ Twilightnutzam · nutzbootEPSS 0.47%via NVD
CVE-2025-13829None
10mo ago

Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshTo…

Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. Critical information retrieved: * APIKEY (1 year user Session) * RefreshTo…

▾ SunlitEPSS 0.30%via NVD
CVE-2025-13813Medium· 5.6
10mo ago

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2

A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The atta…

▾ Sunlitmogublog_project · mogublogEPSS 0.47%via NVD
CVE-2025-48044High· 8.6
11mo ago

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1.

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1.

▾ Twilightash-project · ashEPSS 0.66%via NVD
CVE-2025-48043High· 8.6
11mo ago

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 0.1.1 before 3.6.2.

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 0.1.1 before 3.6.2.

▾ Twilightash-project · ashEPSS 0.39%via NVD
CVE-2025-43784Medium· 6.5
1y ago

Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object entries informat…

Improper Access Control vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows guest users to obtain object entries informat…

▾ Sunlitliferay · digital_experience_platformEPSS 0.26%via NVD
CVE-2025-48042High· 7.1
1y ago

Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ash: from 0.1.1 before 3.5.39.

Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ash: from 0.1.1 before 3.5.39.

▾ Twilightash-project · ashEPSS 0.32%via NVD
CVE-2025-20701High· 8.8PoC
1y ago

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not nee…

▾ MidnightAiroha Technology Corp. · AB156x, AB157x, AB158x, AB159x seriesEPSS 8.7%via NVD
CVE-2025-6018High· 7.8PoC
1y ago

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM)

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the…

▾ Midnightsuse · pam-configEPSS 1.1%via NVD
CVE-2024-10306Medium· 5.4
1y ago

A vulnerability was found in mod_proxy_cluster

A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not restrict IP/host access as `Require ip IP_ADDRESS` would suggest. This mean…

▾ SunlitEPSS 0.33%via NVD
CVE-2025-25040Low· 3.3
1y ago

A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.10…

A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.10…

▾ Sunlithpe · arubaos-cxEPSS 0.13%via NVD
CVE-2024-57969Medium· 4.3
1y ago

app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.

app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.

▾ Sunlitmisp-project · mispEPSS 0.26%via NVD
CVE-2024-54010Low· 3.4
1y ago

A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists

A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this at…

▾ Sunlithpe · arubaos-cxEPSS 0.23%via NVD
CVE-2024-21262Medium· 6.5PoC
1y ago

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC)

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access vi…

▾ Twilightnetapp · oncommand_insightEPSS 0.57%via NVD
CVE-2024-6593Critical· 9.1
2y ago

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained netwo…

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained netwo…

▾ Midnightwatchguard · authentication_gatewayEPSS 0.58%via NVD
CVE-2024-6592Critical· 9.1PoC
2y ago

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…

▾ Abyssalwatchguard · authentication_gatewayEPSS 1.2%via NVD
CVE-2024-46918Medium· 4.9
2y ago

app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.

app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.

▾ Sunlitmisp-project · mispEPSS 0.44%via NVD
CVE-2024-45509Medium· 6.5
2y ago

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

▾ Sunlitmisp-project · mispEPSS 0.40%via NVD
CVE-2024-36265Critical· 9.8
2y ago

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST…

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. An attacker can bypass authentication by sending specially crafted REST…

▾ Midnightapache · submarineEPSS 0.74%via NVD
CVE-2024-23669Medium· 6.5
2y ago

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands …

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands …

▾ Sunlitfortinet · fortiwebmanagerEPSS 0.55%via NVD
CVE-2023-4853High· 8.1
3y ago

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass …

▾ Twilightquarkus · quarkusEPSS 1.4%via NVD
CVE-2023-20269Medium· 5.0CISA KEV
3y ago

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …

▾ Midnightcisco · adaptive_security_appliance_softwareEPSS 25%via NVD
CVE-2022-42724Medium· 4.3
3y ago

app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).

app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).

▾ Sunlitmisp-project · mispEPSS 0.49%via NVD
CVE-2022-0577Medium· 6.5
4y ago

Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy

Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy

▾ Sunlitscrapy · scrapyEPSS 1.3%via OSV
CVE-2021-40639High· 7.5
5y ago

Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.

Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.

▾ Twilightjflyfox · jfinal_cmsEPSS 1.2%via NVD
CVE-2021-29158Medium· 4.9
5y ago

Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.

Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.

▾ Sunlitsonatype · nexus_repository_managerEPSS 0.84%via NVD
CVE-2021-28936High· 7.5
5y ago

The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request

The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending a specially crafted HTTP GET request. The administrator username has to be known (default:admin) whereas no previous …

▾ Twilightacexy · wireless-n_wifi_repeater_firmwareEPSS 2.0%via NVD
CWE-863 vulnerabilities (CVEs) — page 29 · VulnSea