Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,737 CVEs tagged with CWE-862437 Critical, 1,966 High, 6,041 Medium, 292 Low, 1 Unrated.

CVE-2026-7558

Published Jul 9, 2026

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including 4.0.2. This is due to…

CVSS 5.3 · Medium
evidence mentions
9
Buzz score
34.5

CVE-2026-14245

Published Jul 9, 2026

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions…

CVSS 9.8 · Critical
evidence mentions
11
Buzz score
36.4

CVE-2026-12406

Published Jul 9, 2026

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authorization bypass in all versions…

CVSS 5.3 · Medium
evidence mentions
11
Buzz score
36.4

CVE-2026-11359

Published Jul 9, 2026

The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in ve…

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-48492

Published Jul 8, 2026

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can log…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-35552

Published Jul 8, 2026

In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended f…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-31309

Published Jul 8, 2026

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the nod…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
25.8

CVE-2026-8472

Published Jul 8, 2026

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have al…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-7492

Published Jul 8, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-55542

Published Jul 8, 2026

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments…

CVSS 1.3 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-59805

Published Jul 8, 2026

Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sel…

CVSS 7.1 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-14373

Published Jul 8, 2026

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59262

Published Jul 8, 2026

AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing authenticated workspace members to retrieve restricted conte…

CVSS 7.1 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-60124

Published Jul 8, 2026

An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys with event view access to persist data to events they were not…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-56250

Published Jul 8, 2026

Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, enabling retargeting to arbitrary R2 bundle objects. Attack…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-15034

Published Jul 8, 2026

A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to cross-sit…

CVSS 2.1 · Low
evidence mentions
9
Buzz score
29.5

CVE-2026-5356

Published Jul 8, 2026

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 5.4.0. Th…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-12153

Published Jul 8, 2026

The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
31.0

CVE-2026-12097

Published Jul 8, 2026

The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin not properly verifying that a u…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-55433

Published Jul 8, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint rel…

CVSS 5.4 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-55432

Published Jul 8, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `CreateSubAgent` RPC did not valid…

CVSS 5.4 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-59704

Published Jul 7, 2026

Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. Authenticated…

CVSS 7.1 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-58473

Published Jul 7, 2026

Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-55417

Published Jul 7, 2026

Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile option, visiting their profile HTM…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-53730

Published Jul 7, 2026

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @DePermit permission validation…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0
Showing 301-325 of 8,737 CVEsPage 13 of 350