Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,316 CVEs tagged with CWE-863317 Critical, 1,147 High, 1,600 Medium, 249 Low, 3 Unrated.

CVE-2026-13232

Published Jul 10, 2026

Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_fe…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-57218

Published Jul 10, 2026

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.upd…

CVSS 4.9 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-57217

Published Jul 10, 2026

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata…

CVSS 7.0 · High
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-57215

Published Jul 10, 2026

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile…

CVSS 7.0 · High
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-55479

Published Jul 10, 2026

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the legacy single-seat license checkin flow authorizes the action with the checkout permission instead of the ch…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-55475

Published Jul 10, 2026

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid API key to overwrite the create…

CVSS 5.7 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-55462

Published Jul 10, 2026

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UsersController::show() and printInventory() authorize only user viewing before loading and rendering assigned l…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-55472

Published Jul 10, 2026

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locations_fmcs are enabled, the API location creation endpoint de…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-55460

Published Jul 10, 2026

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.delete can directly POST to /us…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-55672

Published Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fail to verify tha…

CVSS 7.4 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-59154

Published Jul 10, 2026

Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct Meteor collection allow rules for Checklists and Checklist…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-55638

Published Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/dashboardGuard.js but omits /codex before next.config.mjs rew…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-39903

Published Jul 10, 2026

Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a s…

CVSS 7.1 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-22659

Published Jul 10, 2026

FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated moderators to perform unauthorized actions on topics in fo…

CVSS 7.2 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-40452

Published Jul 10, 2026

Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticate…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-15332

Published Jul 10, 2026

A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of the component Message Endpoint.…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-15286

Published Jul 10, 2026

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-5069

Published Jul 10, 2026

The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insuffic…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-15320

Published Jul 10, 2026

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pico.go. Performing a manipulati…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-15318

Published Jul 10, 2026

A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqtt.go of the component MQTT Cha…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-59227

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /api/v1/images/edit required only a verified account and did…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-59226

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_automation rehydrated automation owners without rechecking…

CVSS 3.1 · Low
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-59217

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload path accepted metadata.knowledge_id and auto-linked uploaded…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-59212

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _verify_knowledge_file_access only checked read access while file w…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort
Showing 126-150 of 3,316 CVEsPage 6 of 133