Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,517 CVEs tagged with CWE-863342 Critical, 1,224 High, 1,683 Medium, 265 Low, 3 Unrated.

CVE-2026-50529

Published Jul 7, 2026

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validat…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-55435

Published Jul 7, 2026

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy…

CVSS 5.4 · Medium
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-12352

Published Jul 7, 2026

This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-34047

Published Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce th…

CVSS 9.9 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-53642

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Require Email Confirmation" setting is enabled, a logged-in cli…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-32718

Published Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, mutating API validation endpoints are guarded by read…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-54765

Published Jul 6, 2026

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that tar…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-42331

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present in…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-14536

Published Jul 6, 2026

Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required p…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-14716

Published Jul 5, 2026

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. Impacted is the function MethodRouter.Handle of the file internal/gateway/router.go of t…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-28744

Published Jul 3, 2026

Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.

CVSS 8.1 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28740

Published Jul 3, 2026

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.

CVSS 7.1 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-28699

Published Jul 3, 2026

Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.

CVSS 8.1 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-27780

Published Jul 3, 2026

Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-27775

Published Jul 3, 2026

Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for ot…

CVSS 8.8 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-27761

Published Jul 3, 2026

Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens w…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-26231

Published Jul 3, 2026

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able…

CVSS 8.5 · High
evidence mentions
5
Buzz score
27.9

CVE-2026-46730

Published Jul 3, 2026

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release ve…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54998

Published Jul 2, 2026

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

CVSS 8.8 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-8079

Published Jul 2, 2026

In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56842

Published Jul 2, 2026

A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist priv…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-14340

Published Jul 1, 2026

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain writ…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-53492

Published Jul 1, 2026

containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56152

Published Jul 1, 2026

Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under c…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 376-400 of 3,517 CVEsPage 16 of 141