Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,317 CVEs tagged with CWE-863317 Critical, 1,148 High, 1,600 Medium, 249 Low, 3 Unrated.

CVE-2026-47777

Published Jun 15, 2026

Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented to be featured in a…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2016-20075

Published Jun 15, 2026

WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles t…

CVSS 8.7 · High

CVE-2026-34023

Published Jun 15, 2026

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability in the WebSocket communication used by the SafeController…

CVSS 7.1 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-2470

Published Jun 13, 2026

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-54398

Published Jun 12, 2026

An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an o…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-53835

Published Jun 12, 2026

OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated senders to create or update bindings…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-53834

Published Jun 12, 2026

OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to skip allowFrom policy checks. At…

CVSS 8.2 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-53828

Published Jun 12, 2026

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper…

CVSS 7.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-53521

Published Jun 12, 2026

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to before version 2.1.0, PATCH /server/{id} accepts and persist…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49397

Published Jun 12, 2026

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to before version 2.0.14, private services (`EnableShowInService…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47120

Published Jun 12, 2026

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember can fire other users' cron…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46717

Published Jun 12, 2026

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's dashboard supports two user rol…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54397

Published Jun 12, 2026

A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form data and set an event’s sharing_gr…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54362

Published Jun 12, 2026

An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-admin users to view galaxies that should not have been visible to their organis…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54358

Published Jun 12, 2026

An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same organization through the administ…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54357

Published Jun 12, 2026

An improper authorization vulnerability in MISP allowed an authenticated organization administrator to access or modify user settings belonging to site administrator accounts with…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-42604

Published Jun 12, 2026

Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full OpenID Connect configuration—i…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-50008

Published Jun 12, 2026

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList serv…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-47236

Published Jun 12, 2026

Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view and members:view permissions that gates the official invitat…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-44173

Published Jun 12, 2026

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7…

CVSS 5.0 · Medium
evidence mentions
12
Buzz score
40.1
Vendor/product tagsBeta · best-effort

CVE-2026-44169

Published Jun 12, 2026

MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a store…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-7387

Published Jun 12, 2026

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6739

Published Jun 12, 2026

Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patching protected default system rol…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45831

Published Jun 12, 2026

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never ch…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53721

Published Jun 12, 2026

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sens…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 276-300 of 3,317 CVEsPage 12 of 133