VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

871 CVEsRSS

CVE-2026-91851Medium· 5.3
1w ago

Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either:  - its restrict_to_permission_flag matched one…

Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either:  - its restrict_to_permission_flag matched one…

▾ SunlitMISP · MISPEPSS 0.35%via NVD
CVE-2026-91778High· 7.2
1w ago

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker)

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would a…

▾ TwilightOctopus Deploy · Octopus ServerEPSS 0.43%via NVD
CVE-2026-59965High· 7.1PoC
1w ago

Payload Plugins is a collection of plugins designed to enhance Payload CMS

Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts a…

▾ Midnightjhb-software · payload-pluginsEPSS 0.38%via NVD
CVE-2026-54076High· 8.1
1w ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcad…

▾ TwilightArcadeData · arcadedbEPSS 0.50%via NVD
CVE-2026-52819Medium· 6.3PoC
1w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a…

▾ Twilightkimai · kimaiEPSS 0.50%via NVD
CVE-2026-55636Medium· 5.7
1w ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates/configuration.yaml configures the validating webhook with namespace/finalize instead of the Kubernetes resource name…

▾ Sunlitprojectcapsule · capsuleEPSS 0.39%via NVD
CVE-2026-55774Low· 2.1
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known…

▾ Sunlitopenbao · openbaoEPSS 0.56%via NVD
CVE-2026-55701Medium· 6.9
1w ago

The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector

The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiv…

▾ Sunlitopen-telemetry · opentelemetry-collector-contribEPSS 0.70%via NVD
CVE-2026-91181Medium· 6.5
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data …

▾ SunlitMattermost · MattermostEPSS 0.39%via NVD
CVE-2026-90820Medium· 4.3
1w ago

A security vulnerability has been detected in a2aproject a2a-java 1.2.0

A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandl…

▾ Sunlita2aproject · a2a-javaEPSS 0.39%via NVD
CVE-2026-84560Medium· 6.1
1w ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may gain unauthorized access to Bluetooth.

▾ Sunlitapple · ipadosEPSS 0.14%via NVD
CVE-2026-84612Medium· 5.5
1w ago

An authorization issue was addressed with improved access control

An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An ap…

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2026-84540Medium· 5.5
1w ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.15%via NVD
CVE-2026-84628Medium· 5.5
1w ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to access the System Keychain.

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2026-65380Medium· 5.5
1w ago

An issue existed in the handling of snapshots

An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Golden Gate 27. An app may be able to access protected user data.

▾ Sunlitapple · macosEPSS 0.17%via NVD
CVE-2026-84618Medium· 5.5
1w ago

A permissions issue was addressed with improved validation

A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.16%via NVD
CVE-2026-43695Medium· 5.5
1w ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access …

▾ Sunlitapple · ipadosEPSS 0.14%via NVD
CVE-2026-84589Medium· 5.5
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27. An app may be able to modify Privacy preferences.

▾ Sunlitapple · macosEPSS 0.14%via NVD
CVE-2026-65378High· 7.5⚖ disputed
1w ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

▾ Twilightapple · macosEPSS 0.31%via NVD
CVE-2026-43785Medium· 5.5
1w ago

A permissions issue was addressed with additional restrictions

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to modify a file it only ha…

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2026-84617Medium· 5.5
1w ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27. An app may be able to access…

▾ Sunlitapple · ipadosEPSS 0.14%via NVD
CVE-2026-84601Medium· 5.5
1w ago

A permissions issue was addressed with improved state management

A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Apple Intelligence security prompts.

▾ Sunlitapple · macosEPSS 0.14%via NVD
CVE-2026-65404Medium· 5.5
1w ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A malicious application ma…

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2026-43737Medium· 5.5
1w ago

An authorization issue was addressed with improved validation

An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to …

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2026-65393Medium· 5.5
1w ago

A permissions issue was addressed with improved validation

A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data.

▾ Sunlitapple · xcodeEPSS 0.16%via NVD
CVE-2026-19816High· 7.1
1w ago

A flaw was found in PackageKit

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transac…

▾ TwilightFedora · PackageKitEPSS 0.10%via NVD
CVE-2026-90942Critical· 9.6PoC
1w ago

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key…

▾ Abyssalcasdoor · casdoorEPSS 0.28%via NVD
CVE-2026-90806Medium· 6.3
1w ago

A vulnerability has been found in DjangoCRM django-crm up to 1.2

A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing au…

▾ SunlitDjangoCRM · django-crmEPSS 0.37%via NVD
CVE-2023-50461High· 8.8
1w ago

An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3

An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured …

▾ TwilightTYPO3 · direct_mailEPSS 0.33%via NVD
CVE-2023-50460Medium· 5.4
1w ago

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any f…

▾ SunlitTYPO3 · femanagerEPSS 0.24%via NVD
CWE-863 vulnerabilities (CVEs) — page 6 · VulnSea