VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

871 CVEsRSS

CVE-2026-84098Medium· 6.5
4d ago

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and …

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and …

▾ SunlitEPSS 0.21%via NVD
CVE-2026-63131Medium· 6.0
4d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could evaluate a broader wildcard ACL grant before more-specific trailing-wildcard ACL paths with capabilities = ["deny"] f…

▾ Sunlitopenbao · openbaoEPSS 0.35%via NVD
CVE-2026-95814High· 8.1
5d ago

Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization …

Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization …

▾ Twilightdani-garcia · vaultwardenEPSS 0.43%via NVD
CVE-2026-77425Medium· 4.3PoC
5d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUp…

▾ TwilightUnleash · unleashEPSS 0.23%via NVD
CVE-2026-79767Medium· 5.5
5d ago

Gardener implements the automated management and operation of Kubernetes clusters as a service

Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check com…

▾ Sunlitgardener · gardenerEPSS 0.39%via NVD
CVE-2026-75745Critical· 10.0
5d ago

Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrar…

▾ MidnightAdobe · AEM 6.5 Forms JEEEPSS 1.2%via NVD
CVE-2026-75728Critical· 9.1
5d ago

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code…

▾ Midnightadobe · campaignEPSS 1.0%via NVD
CVE-2026-75723Critical· 10.0
5d ago

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code…

▾ Midnightadobe · campaignEPSS 1.2%via NVD
CVE-2026-77251High· 8.3PoC
5d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence se…

▾ Midnightsooperset · mcp-atlassianEPSS 0.25%via NVD
CVE-2026-75608High· 7.7
5d ago

Frigate is an open source network video recorder

Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does not require an administrator role for G…

▾ Twilightblakeblackshear · frigateEPSS 0.51%via NVD
CVE-2026-95654High· 7.4
5d ago

Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance

Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a leaked or forwarded invitation link can…

▾ TwilightDavid-Crty · DatabasementEPSS 0.51%via NVD
CVE-2026-6922High· 7.1
5d ago

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.2.1

The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.2.1. This is due to an operator precedence bug in the post-type guard within the trash…

▾ Twilightwptb · WP Table Builder – Drag & Drop Table BuilderEPSS 0.56%via NVD
CVE-2026-59815Medium· 4.3PoC
6d ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to items with a share ID when any share_users row exis…

▾ Twilightlaurent22 · joplinEPSS 0.23%via NVD
CVE-2026-73553High· 7.5PoC
6d ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's router strips the semicolon suffix befo…

▾ Midnightenvoyproxy · envoyEPSS 0.52%via NVD
CVE-2026-62247Medium· 6.5
6d ago

Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets

Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy when a private-channel clien…

▾ Sunlitsupabase · realtimeEPSS 0.45%via NVD
CVE-2026-91164Medium· 4.3
6d ago

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken without enforcing the owning…

▾ Sunlitwarp-tech · warpgateEPSS 0.42%via NVD
CVE-2026-61744Medium· 6.5
6d ago

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthen…

▾ Sunlitinventree · InvenTreeEPSS 0.51%via NVD
CVE-2026-77560High· 8.1
6d ago

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege u…

▾ Twilighttinyauthapp · tinyauthEPSS 0.61%via NVD
CVE-2026-63342Medium· 6.3
6d ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-ta…

▾ Sunlithatchet-dev · hatchetEPSS 0.31%via NVD
CVE-2026-55563High· 8.9PoC
6d ago

Feast is the open source feature store for AI and machine learning

Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_tests.yml uses pull_request_target with the synchronize event and preserves ok-to-test, approved, or lgtm labels across…

▾ Midnightfeast-dev · feastEPSS 0.50%via NVD
CVE-2026-88978Medium· 4.3
6d ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and …

▾ Sunlithatchet-dev · hatchetEPSS 0.28%via NVD
CVE-2026-71543High· 7.2
6d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated…

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.42%via NVD
CVE-2026-55625Medium· 4.9
6d ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and…

▾ Sunlitgocd · gocdEPSS 0.46%via NVD
CVE-2026-55060Low· 3.7
6d ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source c…

▾ Sunlitgocd · gocdEPSS 0.35%via NVD
CVE-2026-52742Medium· 5.1
6d ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for gro…

▾ Sunlitgocd · gocdEPSS 0.52%via NVD
CVE-2026-52740Medium· 5.3
6d ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with no…

▾ Sunlitgocd · gocdEPSS 0.43%via NVD
CVE-2026-80110High· 8.1
6d ago

A flaw was found in pki-core

A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to ove…

▾ TwilightRed Hat · pki-coreEPSS 0.24%via NVD
CVE-2026-52743Medium· 4.3
6d ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can gu…

▾ Sunlitgocd · gocdEPSS 0.34%via NVD
CVE-2026-93954Medium· 4.3PoC
1w ago

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of …

▾ Twilightgrimmory-tools · grimmoryEPSS 0.39%via NVD
CVE-2026-1242Medium· 4.3
1w ago

The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator…

The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator…

▾ Sunlitblockspare · BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business WebsitesEPSS 0.18%via NVD
CWE-863 vulnerabilities (CVEs) — page 3 · VulnSea