Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,738 CVEs tagged with CWE-862438 Critical, 1,966 High, 6,041 Medium, 292 Low, 1 Unrated.

CVE-2026-57340

Published Jun 29, 2026

Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-57339

Published Jun 29, 2026

Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-57335

Published Jun 29, 2026

Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-57334

Published Jun 29, 2026

Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-57332

Published Jun 29, 2026

Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-57327

Published Jun 29, 2026

Subscriber Broken Access Control in MainWP <= 6.1.1 versions.

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-2902

Published Jun 29, 2026

Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090…

CVSS 8.3 · High

CVE-2026-13537

Published Jun 29, 2026

A vulnerability was found in CodeAstro Human Resource Management System 1.0. Impacted is an unknown function. The manipulation results in cross-site request forgery. The attack ma…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13484

Published Jun 28, 2026

A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schem…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3
Vendor/product tagsBeta · best-effort

CVE-2026-9233

Published Jun 27, 2026

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due…

CVSS 4.3 · Medium
evidence mentions
13
Buzz score
37.9

CVE-2026-3462

Published Jun 27, 2026

The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all v…

CVSS 6.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-12471

Published Jun 27, 2026

The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11.…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-12432

Published Jun 27, 2026

The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action.…

CVSS 5.3 · Medium
evidence mentions
11
Buzz score
36.4

CVE-2026-11773

Published Jun 27, 2026

The Masteriyo LMS – LMS Course Builder, Quizzes & Certificates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.1. This is due…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
32.3

CVE-2026-11364

Published Jun 27, 2026

The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and including 0.8.9. T…

CVSS 4.3 · Medium
evidence mentions
9
Buzz score
34.5

CVE-2026-12404

Published Jun 27, 2026

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plug…

CVSS 5.3 · Medium
evidence mentions
9
Buzz score
34.5

CVE-2026-50137

Published Jun 26, 2026

Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) ca…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55838

Published Jun 26, 2026

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.7 and earlier, the real-time metrics endpoint at /rustfs/admin/v3/metrics is accessible to any valid IAM…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-55189

Published Jun 26, 2026

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read and probe handlers dispatch dire…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55188

Published Jun 26, 2026

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. Th…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49991

Published Jun 26, 2026

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket can exploit a path traversal v…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47193

Published Jun 26, 2026

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical field values without enforcing…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44734

Published Jun 26, 2026

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController.…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-57518

Published Jun 26, 2026

Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbit…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-12411

Published Jun 26, 2026

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume vi…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 401-425 of 8,738 CVEsPage 17 of 350