VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

871 CVEsRSS

CVE-2026-92402Medium· 6.3
1w ago

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component top.upstudy.crm.controller.UserController. The …

▾ SunlitChangeWeDer · crmEPSS 0.37%via NVD
CVE-2026-20072Medium· 4.9
1w ago

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to. &nb…

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.37%via NVD
CVE-2026-76438Medium· 6.5
1w ago

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerabili…

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerabili…

▾ SunlitCisco · Cisco BroadWorksEPSS 0.56%via NVD
CVE-2026-61709Medium· 5.3
1w ago

OpenFGA is an authorization and permission engine built for developers

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not e…

▾ Sunlitopenfga · openfgaEPSS 0.35%via NVD
CVE-2026-92130Low· 3.1
1w ago

Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture cred…

Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture cred…

▾ SunlitJenkins Project · Jenkins Pipeline: Multibranch PluginEPSS 0.22%via NVD
CVE-2026-73469Medium· 5.8
1w ago

When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop

When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on…

▾ SunlitArista Networks · EOSEPSS 0.29%via NVD
CVE-2026-19640Medium· 4.2
1w ago

On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissi…

On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissi…

▾ SunlitArista Networks · EOSEPSS 0.19%via NVD
CVE-2026-27552High· 8.1
1w ago

A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.

A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.

▾ TwilightPepperl+Fuchs · ICE2-8IOL1-G65L-V1DEPSS 0.60%via NVD
CVE-2026-79708High· 8.5
1w ago

GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to …

GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to …

▾ TwilightGitLab · GitLabEPSS 0.34%via NVD
CVE-2026-73460Medium· 6.1
1w ago

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may r…

▾ SunlitArista Networks · EOSEPSS 0.20%via NVD
CVE-2026-76863Medium· 4.3
1w ago

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can access th…

▾ SunlitNetcore · NR255-VEPSS 0.28%via NVD
GHSA-5648-rgj9-v224High· 8.1
1w ago

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS

▾ Twilightzereight · @zereight/mcp-gitlabvia GHSA
CVE-2026-91735High· 8.3
1w ago

Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium secu…

▾ Twilightgoogle · chromeEPSS 0.31%via NVD
CVE-2026-91734High· 7.4
1w ago

Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program

Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.10%via NVD
CVE-2026-87144High· 7.6
1w ago

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privile…

▾ Twilightoracle · hyperion_data_relationship_managementEPSS 0.27%via NVD
CVE-2026-87141High· 7.7
1w ago

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privile…

▾ Twilightoracle · hyperion_data_relationship_managementEPSS 0.35%via NVD
CVE-2026-87137High· 7.6
1w ago

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privile…

▾ Twilightoracle · hyperion_data_relationship_managementEPSS 0.27%via NVD
CVE-2026-90971Medium· 6.5
1w ago

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata netwo…

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata netwo…

▾ SunlitDevolutions · ServerEPSS 0.34%via NVD
CVE-2026-13210High· 7.7
1w ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables ou…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to access CI/CD variables ou…

▾ TwilightGitLab · GitLabEPSS 0.21%via NVD
CVE-2026-63443High· 8.3
1w ago

Coder allows organizations to provision remote development environments via Terraform

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected…

▾ Twilightcoder · coderEPSS 0.76%via NVD
CVE-2026-91983Medium· 4.3PoC
1w ago

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restric…

▾ Twilightgo-vikunja · vikunjaEPSS 0.30%via NVD
CVE-2026-65831High· 7.7
1w ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions …

▾ TwilightArcadeData · arcadedbEPSS 0.60%via NVD
CVE-2026-88617Critical· 9.8
1w ago

SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint

SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.

▾ MidnightEPSS 0.61%via NVD
CVE-2026-88616High· 8.8PoC
1w ago

An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /wo…

An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /wo…

▾ MidnightEPSS 0.69%via NVD
CVE-2026-16140High· 8.8
1w ago

OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption k…

OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption k…

▾ TwilightOpenBMC · phosphor-net-ipmidEPSS 0.27%via NVD
CVE-2026-91998Critical· 9.9PoC
1w ago

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…

▾ Abyssalcasdoor · casdoorEPSS 0.59%via NVD
CVE-2026-57137High· 8.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped A…

▾ MidnightMervinPraison · PraisonAIEPSS 0.51%via NVD
CVE-2026-57134High· 8.2PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth …

▾ MidnightMervinPraison · PraisonAIEPSS 0.41%via NVD
CVE-2026-57133High· 8.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the compl…

▾ MidnightMervinPraison · PraisonAIEPSS 0.80%via NVD
CVE-2026-57136High· 8.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExec…

▾ MidnightMervinPraison · PraisonAIEPSS 0.55%via NVD
CWE-863 vulnerabilities (CVEs) — page 5 · VulnSea