Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,737 CVEs tagged with CWE-862437 Critical, 1,966 High, 6,041 Medium, 292 Low, 1 Unrated.

CVE-2026-50007

Published Jul 7, 2026

Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared user with user_access on a budget file to perform owner-only…

CVSS 7.2 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-59708

Published Jul 7, 2026

The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full po…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-59709

Published Jul 7, 2026

Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-on…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-11340

Published Jul 7, 2026

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: before release.Maste…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8377

Published Jul 7, 2026

Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue affects…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-34048

Published Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authent…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-53647

Published Jul 7, 2026

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endpoint is accessible without aut…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-53643

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unauthorized actions via admin API…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-53640

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff accounts may read sensitive data via admin API endpoints that…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-34050

Published Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-14800

Published Jul 6, 2026

A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affected element is an unknown function. This manipulation causes…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-6509

Published Jul 5, 2026

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue affects Pardus Update: from <…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-27783

Published Jul 3, 2026

Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-27771

Published Jul 3, 2026

Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.

CVSS 8.2 · High
evidence mentions
8
Buzz score
42.0

CVE-2026-25714

Published Jul 3, 2026

Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-25038

Published Jul 3, 2026

Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

CVSS 7.5 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-14460

Published Jul 3, 2026

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11398

Published Jul 3, 2026

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.6.1. This is…

CVSS 5.3 · Medium
evidence mentions
11
Buzz score
36.4

CVE-2026-9230

Published Jul 3, 2026

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due…

CVSS 4.3 · Medium
evidence mentions
15
Buzz score
39.2

CVE-2026-12557

Published Jul 3, 2026

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly veri…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-12729

Published Jul 3, 2026

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.3.0. Th…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
32.3

CVE-2026-59097

Published Jul 2, 2026

Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to create default due-date records in any project by exploiting unp…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-50282

Published Jul 2, 2026

Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue wher…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-57760

Published Jul 2, 2026

Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-57750

Published Jul 2, 2026

Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Showing 326-350 of 8,737 CVEsPage 14 of 350