Falhas do tipo CWE-639
1.572 resultadosCVE-2026-55197HIGHHermes WebUI < 0.51.443 - Broken Access Control in /api/session EndpointEPSS 0.3%CVE-2025-69202MEDIUMaxios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary HeaderEPSS 0.3%CVE-2026-55198HIGHHermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export EndpointEPSS 0.3%CVE-2026-22383HIGHWordPress PawFriends - Pet Shop and Veterinary WordPress theme theme <= 1.3 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2024-31898MEDIUMIBM InfoSphere Information Server data modificationEPSS 0.3%CVE-2026-11987MEDIUMDokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' ParameterEPSS 0.3%CVE-2026-39968HIGHTypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview EndpointEPSS 0.3%CVE-2026-25120MEDIUMGogs Allows Cross-Repository Comment Deletion via DeleteCommentEPSS 0.3%CVE-2026-6586MEDIUMTransformerOptimus SuperAGI Budget Endpoint budget.py update_budget authorizationEPSS 0.3%CVE-2026-45671HIGHOpen WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletionEPSS 0.3%CVE-2026-3307MEDIUMAuthorization bypass in GitHub Enterprise Server secret scanning push protection allows cross-repository modification of delegated bypass reviewersEPSS 0.3%CVE-2026-46390MEDIUMHAX CMS has Unauthenticated Git Access via User-Controlled KeyEPSS 0.3%CVE-2025-39434MEDIUMWordPress Avatar plugin <= 0.1.4 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2026-6571MEDIUMkodcloud KodExplorer systemRole.class.php roleGroupAction authorizationEPSS 0.3%CVE-2025-67919MEDIUMWordPress Woffice Core plugin <= 5.4.30 - Insecure Direct Object References (IDOR) vulnerabilityEPSS 0.3%CVE-2025-43827MEDIUMInsecure Direct Object Reference (IDOR) vulnerability with audit events in Liferay Portal 7.4.0 through 7.4.3.117, and older unsupported verEPSS 0.3%CVE-2026-32694MEDIUMInsecure Direct Object Reference attack via predictable secret ID in JujuEPSS 0.3%CVE-2025-9836MEDIUMmacrozheng mall paySuccess authorizationEPSS 0.3%CVE-2026-1947HIGHNEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_idEPSS 0.3%CVE-2026-40907MEDIUMWWBN AVideo has IDOR in Live Restreams list.json.php that Exposes Other Users' Stream Keys and OAuth TokensEPSS 0.3%