Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,427 CVEs tagged with CWE-863327 Critical, 1,185 High, 1,650 Medium, 262 Low, 3 Unrated.

CVE-2026-9640

Published Jun 26, 2026

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during…

CVSS 7.2 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-54096

Published Jun 25, 2026

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.7, `POST /api/share/<path>`…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54091

Published Jun 25, 2026

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, File Browser's public sha…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-55411

Published Jun 25, 2026

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated endpoint…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54573

Published Jun 25, 2026

Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess function uses ctx.originalUrl to verify if an API key or OAuth…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-5952

Published Jun 25, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could hav…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-5796

Published Jun 25, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-11379

Published Jun 25, 2026

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0934

Published Jun 25, 2026

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have al…

CVSS 3.8 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-52808

Published Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/repos/:owner/:repo/wiki, and P…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-52795

Published Jun 24, 2026

Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private repository they have no access to, because the access check in th…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-56232

Published Jun 24, 2026

Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareKey function. Attackers can byp…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-48493

Published Jun 23, 2026

Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves an…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-54518

Published Jun 23, 2026

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.pr…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-54517

Published Jun 23, 2026

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deseri…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-46549

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_scope and oauth_granted_resources to the request user, but t…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-23513

Published Jun 23, 2026

FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-construction flaw in client list endpoints allowed authenticated clie…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-54761

Published Jun 23, 2026

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in Traefik's Kubernetes Gateway provider affecting the crossP…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-54555

Published Jun 23, 2026

rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter did not conservatively split or reject several shell constr…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54321

Published Jun 23, 2026

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox previews that were switched from pu…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54320

Published Jun 23, 2026

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.184.0, organization invitations could be accepted (and decli…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54324

Published Jun 23, 2026

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, a cross-tenant authorization flaw in Daytona's notifi…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-54022

Published Jun 23, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ydoc:document:join Socket.IO handler checks note ownership…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54021

Published Jun 23, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, several direct, index-addressed Ollama proxy routes accept a cal…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49983

Published Jun 23, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permission. You can deny it with --deny-env, or restrict it to a…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 326-350 of 3,427 CVEsPage 14 of 138