Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,366 CVEs tagged with CWE-863324 Critical, 1,165 High, 1,620 Medium, 254 Low, 3 Unrated.

CVE-2026-67341

Published Aug 1, 2026

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute ar…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-67310

Published Aug 1, 2026

OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm a…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-2411

Published Aug 1, 2026

Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to BT_GATT_PERM_READ, and a Chara…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-18394

Published Jul 31, 2026

Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG b…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-54707

Published Jul 31, 2026

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/De…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-18203

Published Jul 31, 2026

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, th…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-14929

Published Jul 31, 2026

The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overw…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62323

Published Jul 31, 2026

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-55502

Published Jul 31, 2026

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55499

Published Jul 31, 2026

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-14538

Published Jul 31, 2026

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authe…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14537

Published Jul 31, 2026

Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protect…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-10031

Published Jul 30, 2026

SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permit…

CVSS 2.3 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-67528

Published Jul 30, 2026

OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/custom_options/:id resolved CustomOption records by global numeric id and allowed U…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-65835

Published Jul 30, 2026

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in…

CVSS 6.6 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-67347

Published Jul 30, 2026

Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-location.service.ts and asset.service.ts update methods that a…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-41187

Published Jul 30, 2026

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and thei…

CVSS 6.2 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-14923

Published Jul 30, 2026

The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a REST route that creates and updates posts, because of an op…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48449

Published Jul 30, 2026

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-67439

Published Jul 29, 2026

OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGe…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-65975

Published Jul 29, 2026

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and 2.0.0b1 up to but not in…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-6336

Published Jul 29, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2025-14562

Published Jul 29, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have…

CVSS 3.1 · Low
evidence mentions
3
Buzz score
25.4

CVE-2026-18236

Published Jul 29, 2026

A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session h…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54693

Published Jul 29, 2026

ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone self-management API…

CVSS 8.2 · High
evidence mentions
6
Buzz score
24.5
Showing 1-25 of 3,366 CVEsPage 1 of 135