Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

9,181 CVEs tagged with CWE-862482 Critical, 2,118 High, 6,279 Medium, 301 Low, 1 Unrated.

CVE-2026-27377

Published Jul 23, 2026

Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.

CVSS 6.7 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-27355

Published Jul 23, 2026

Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-25466

Published Jul 23, 2026

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-25427

Published Jul 23, 2026

Subscriber Broken Access Control in eRoom <= 1.7.1 versions.

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-25424

Published Jul 23, 2026

Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-15827

Published Jul 23, 2026

The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-jso…

CVSS 5.3 · Medium
evidence mentions
11
Buzz score
36.4

CVE-2026-15015

Published Jul 23, 2026

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not p…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
32.3

CVE-2026-59677

Published Jul 23, 2026

A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in u…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-12082

Published Jul 23, 2026

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-13078

Published Jul 22, 2026

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to rea…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7328

Published Jul 22, 2026

Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local att…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65011

Published Jul 22, 2026

Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated us…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-16544

Published Jul 22, 2026

A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workf…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-63262

Published Jul 22, 2026

Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-63143

Published Jul 21, 2026

Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workfl…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-63141

Published Jul 21, 2026

Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privilege…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-61267

Published Jul 21, 2026

Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65055

Published Jul 21, 2026

Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full member roster and internal workflow configuration of any pri…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-63092

Published Jul 21, 2026

kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any authenticated Kirby Panel user to retrieve the full plaintex…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-47688

Published Jul 21, 2026

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47657

Published Jul 21, 2026

HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenti…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-47416

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspace…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-47413

Published Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0
Showing 501-525 of 9,181 CVEsPage 21 of 368