Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

9,122 CVEs tagged with CWE-862479 Critical, 2,094 High, 6,248 Medium, 300 Low, 1 Unrated.

CVE-2026-11876

Published Jul 21, 2026

In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-6792

Published Jul 21, 2026

Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65007

Published Jul 21, 2026

The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-1372

Published Jul 21, 2026

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.0.0 This is due to missing capability checks on…

CVSS 4.3 · Medium
evidence mentions
7
Buzz score
32.3

CVE-2026-8593

Published Jul 21, 2026

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users without permissions to view an…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14185

Published Jul 21, 2026

The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-generation settings handlers, allowing authenticated users…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-13694

Published Jul 21, 2026

The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing unauthenticated attackers to…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-57494

Published Jul 20, 2026

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate ano…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55550

Published Jul 20, 2026

NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55544

Published Jul 20, 2026

NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47129

Published Jul 20, 2026

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deacti…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-44585

Published Jul 20, 2026

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied service i…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45295

Published Jul 20, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-58482

Published Jul 20, 2026

Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-64622

Published Jul 20, 2026

Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox GET read routes, so even when…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-63758

Published Jul 20, 2026

SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-63741

Published Jul 20, 2026

SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauthenticated attackers can create…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-13432

Published Jul 20, 2026

The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subscriber-level access or higher t…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-12973

Published Jul 20, 2026

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated user…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-12723

Published Jul 20, 2026

The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-11868

Published Jul 20, 2026

The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, a…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-16216

Published Jul 19, 2026

A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-16215

Published Jul 19, 2026

A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulati…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-16197

Published Jul 18, 2026

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go o…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-16123

Published Jul 18, 2026

A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
27.3
Showing 476-500 of 9,122 CVEsPage 20 of 365