Skip to main content

CWE archive

CWE-639 CVEs

Programmatic archive

2,170 CVEs tagged with CWE-639164 Critical, 678 High, 1,177 Medium, 149 Low, 2 Unrated.

CVE-2026-54568

Published Jul 16, 2026

Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE cou…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-59237

Published Jul 16, 2026

Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2025-71388

Published Jul 16, 2026

stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including th…

CVSS 7.6 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-35147

Published Jul 16, 2026

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12906

Published Jul 16, 2026

The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users wi…

CVSS 2.7 · Low
evidence mentions
2
Buzz score
21.0

CVE-2026-12510

Published Jul 16, 2026

The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-l…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-15909

Published Jul 16, 2026

A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipula…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-55234

Published Jul 15, 2026

Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swim…

CVSS 8.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-53447

Published Jul 15, 2026

Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export thr…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-54052

Published Jul 15, 2026

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-52869

Published Jul 15, 2026

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server…

CVSS 7.1 · High
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-58660

Published Jul 15, 2026

Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-s…

CVSS 7.2 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-48799

Published Jul 15, 2026

Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authenticity against the payment provider shared secret and reads th…

CVSS 7.7 · High
evidence mentions
4
Buzz score
26.1

CVE-2025-32781

Published Jul 15, 2026

Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and na…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-44986

Published Jul 15, 2026

Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embed…

CVSS 9.9 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-61836

Published Jul 15, 2026

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key derivation in api/src/utils/get-c…

CVSS 8.6 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-59259

Published Jul 15, 2026

n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling caused by a mismatch between the static validation check a…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-59254

Published Jul 15, 2026

n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outside credentials scope. Authenti…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-59236

Published Jul 15, 2026

Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allow…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-59235

Published Jul 15, 2026

Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Prospero Fl…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-11580

Published Jul 15, 2026

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing u…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-59733

Published Jul 14, 2026

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authori…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-15637

Published Jul 14, 2026

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-15058

Published Jul 14, 2026

Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a dir…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-52841

Published Jul 14, 2026

Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider…

CVSS 3.1 · Low
evidence mentions
2
Buzz score
16.0
Showing 176-200 of 2,170 CVEsPage 8 of 87