VulnSea

CWE-863

CVEs classified under CWE-863, newest first.

874 CVEsRSS

CVE-2026-86752Medium· 5.4
2w ago

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permi…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2026-85978Critical· 9.8
2w ago

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to …

▾ MidnightPerforce · AkanaEPSS 1.4%via NVD
CVE-2026-61907Medium· 4.3
2w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or…

▾ Sunlitcyrusimap · Cyrus IMAPEPSS 0.21%via NVD
CVE-2026-86753Medium· 4.3
2w ago

snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint

snipe-it versions before 8.7.0 fail to validate the requestable flag for asset models in the POST /account/request/asset_model/{modelId} endpoint. Authenticated users can bypass administrative restrictions and create checkout requests fo…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.28%via NVD
CVE-2026-80341Medium· 5.9
2w ago

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's st…

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.26 does not verify that a stored payment method belongs to the user attaching it, allowing any authenticated user, such as a subscriber, to bind another customer's st…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-87075High· 8.1
2w ago

Tanium addressed an improper access controls vulnerability in Comply.

Tanium addressed an improper access controls vulnerability in Comply.

▾ Twilighttanium · complyEPSS 0.38%via NVD
CVE-2026-87046Medium· 4.3
2w ago

Tanium addressed an improper access controls vulnerability in Comply.

Tanium addressed an improper access controls vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.25%via NVD
CVE-2026-14892Medium· 4.3
2w ago

Tanium addressed an improper access controls vulnerability in Tanium Server.

Tanium addressed an improper access controls vulnerability in Tanium Server.

▾ SunlitTanium · Tanium ServerEPSS 0.19%via NVD
CVE-2026-87447Medium· 6.5
2w ago

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.26%via NVD
CVE-2026-87651Medium· 4.3⚖ disputed
2w ago

Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page

Incorrect authorization in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-87492Critical· 9.6PoC
2w ago

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 0.44%via NVD
CVE-2026-87515Medium· 6.5
2w ago

Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-87499High· 8.1
2w ago

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-87465Medium· 4.2
2w ago

Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page

Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.22%via NVD
CVE-2026-87652Low· 3.1⚖ disputed
2w ago

Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page

Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-87580Medium· 6.5
2w ago

Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page

Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chro…

▾ Sunlitgoogle · chromeEPSS 0.28%via NVD
CVE-2026-87577Medium· 4.3
2w ago

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-87485Low· 3.1⚖ disputed
2w ago

Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page

Incorrect authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-87481High· 8.3
2w ago

Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page…

Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page…

▾ Twilightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-87476Medium· 6.5
2w ago

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.31%via NVD
CVE-2026-87471High· 8.1
2w ago

Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-87466Medium· 4.3
2w ago

Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-87508Medium· 4.3⚖ disputed
2w ago

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-87452Low· 3.1
2w ago

Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page

Incorrect authorization in GPU in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially obtain cross-origin data via a crafted HTML page. (Chromium security sever…

▾ Sunlitgoogle · chromeEPSS 0.22%via NVD
CVE-2026-87432Medium· 4.2⚖ disputed
2w ago

Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page

Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.22%via NVD
CVE-2026-87644High· 8.3
2w ago

Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the …

Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the …

▾ Twilightgoogle · chromeEPSS 0.39%via NVD
CVE-2026-87594Medium· 5.3
2w ago

Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page

Incorrect authorization in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-87589Medium· 6.5
2w ago

Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page

Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity…

▾ Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-87570High· 8.8
2w ago

Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted file

Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted file. (Chromium s…

▾ Twilightgoogle · chromeEPSS 0.31%via NVD
CVE-2026-87540Medium· 5.4
2w ago

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.23%via NVD
CWE-863 vulnerabilities (CVEs) — page 9 · VulnSea