Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,738 CVEs tagged with CWE-862438 Critical, 1,966 High, 6,041 Medium, 292 Low, 1 Unrated.

CVE-2026-27409

Published Jul 1, 2026

Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-23537

Published Jul 1, 2026

A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the ser…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
29.1

CVE-2026-27435

Published Jul 1, 2026

Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-12435

Published Jul 1, 2026

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to t…

CVSS 4.3 · Medium
evidence mentions
9
Buzz score
34.5

CVE-2026-1239

Published Jul 1, 2026

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-13468

Published Jul 1, 2026

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is…

CVSS 7.5 · High
evidence mentions
9
Buzz score
34.5

CVE-2026-12902

Published Jul 1, 2026

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.7. This is due…

CVSS 4.3 · Medium
evidence mentions
11
Buzz score
36.4

CVE-2026-12133

Published Jul 1, 2026

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authorization to Arbitrary Group Deletion in versions up to, and i…

CVSS 4.3 · Medium
evidence mentions
11
Buzz score
36.4

CVE-2026-12113

Published Jul 1, 2026

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filte…

CVSS 4.3 · Medium
evidence mentions
9
Buzz score
34.5

CVE-2026-14156

Published Jun 30, 2026

Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origi…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-58448

Published Jun 30, 2026

yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supp…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-9132

Published Jun 30, 2026

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did not have…

CVSS 6.0 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-58377

Published Jun 30, 2026

JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-58373

Published Jun 30, 2026

CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows authenticated attackers to enumerate quality report identifier…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-58176

Published Jun 30, 2026

RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without any permission check: the contro…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-58168

Published Jun 30, 2026

DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools functi…

CVSS 7.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-58167

Published Jun 30, 2026

Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HTTP bearer tokens, HTTP basic-auth passwords, and mTLS clien…

CVSS 7.1 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-58165

Published Jun 30, 2026

OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment manageme…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-54475

Published Jun 30, 2026

Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-12349

Published Jun 30, 2026

The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missin…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
32.3

CVE-2026-57498

Published Jun 29, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-57954

Published Jun 29, 2026

Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-57952

Published Jun 29, 2026

Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_w…

CVSS 6.0 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-57949

Published Jun 29, 2026

ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that al…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-57946

Published Jun 29, 2026

Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the R…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
24.4
Showing 376-400 of 8,738 CVEsPage 16 of 350