Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,347 CVEs tagged with CWE-863323 Critical, 1,162 High, 1,606 Medium, 253 Low, 3 Unrated.

CVE-2026-48449

Published Jul 30, 2026

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-67439

Published Jul 29, 2026

OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGe…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-65975

Published Jul 29, 2026

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and 2.0.0b1 up to but not in…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-6336

Published Jul 29, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2025-14562

Published Jul 29, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have…

CVSS 3.1 · Low
evidence mentions
3
Buzz score
25.4

CVE-2026-18236

Published Jul 29, 2026

A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session h…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54693

Published Jul 29, 2026

ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API…

CVSS 8.2 · High
evidence mentions
6
Buzz score
24.5

CVE-2026-18255

Published Jul 29, 2026

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker wit…

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-44944

Published Jul 29, 2026

An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects open-iscsi: from ? through 66…

CVSS 8.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-58159

Published Jul 29, 2026

Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-10656

Published Jul 29, 2026

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-58156

Published Jul 29, 2026

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-66064

Published Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-54719

Published Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did n…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-48396

Published Jul 28, 2026

Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vul…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48390

Published Jul 28, 2026

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read a…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-7868

Published Jul 28, 2026

IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14167

Published Jul 28, 2026

A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-43672

Published Jul 27, 2026

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application ma…

CVSS 7.1 · High
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-42016

Published Jul 27, 2026

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-17568

Published Jul 27, 2026

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership manageme…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-17530

Published Jul 27, 2026

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/ast…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-17529

Published Jul 27, 2026

A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument r…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-59689

Published Jul 27, 2026

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-17039

Published Jul 24, 2026

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing…

CVSS 3.1 · Low
evidence mentions
8
Buzz score
33.5
Showing 1-25 of 3,347 CVEsPage 1 of 134