Skip to main content

CWE archive

CWE-639 CVEs

Programmatic archive

2,083 CVEs tagged with CWE-639160 Critical, 653 High, 1,130 Medium, 138 Low, 2 Unrated.

CVE-2026-57510

Published Jul 28, 2026

SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-49258

Published Jul 28, 2026

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by th…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-18028

Published Jul 28, 2026

The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of an event in just a few clicks. This view did not properly…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-16797

Published Jul 28, 2026

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-59240

Published Jul 27, 2026

The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notification/delete/{id}`. The flaw…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-48052

Published Jul 27, 2026

Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organization can delete or rename tags be…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-17570

Published Jul 27, 2026

Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafte…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-17531

Published Jul 27, 2026

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Un…

CVSS 1.3 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-59546

Published Jul 27, 2026

Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59539

Published Jul 27, 2026

Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-17527

Published Jul 27, 2026

In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on th…

CVSS 7.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-66412

Published Jul 27, 2026

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to by supplying…

CVSS 7.1 · High
evidence mentions
4
Buzz score
27.2
Public PoC observed

CVE-2026-66013

Published Jul 25, 2026

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-65710

Published Jul 24, 2026

sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decry…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-65709

Published Jul 24, 2026

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwri…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-65708

Published Jul 24, 2026

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to ac…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-17059

Published Jul 24, 2026

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-13464

Published Jul 24, 2026

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.0.14…

CVSS 5.3 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-15630

Published Jul 23, 2026

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorizatio…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-65699

Published Jul 23, 2026

AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by su…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
17.5

CVE-2026-47755

Published Jul 23, 2026

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve p…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-47743

Published Jul 23, 2026

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS.…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-65696

Published Jul 23, 2026

Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-65917

Published Jul 23, 2026

CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (d…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-65501

Published Jul 23, 2026

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 2,083 CVEsPage 1 of 84