CVE-2025-26788

CVSS v3 Score
8.4
High

Vulnerability Description

StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.

CVSS:8.3(High)

OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data within the web application. Specifically, the is_maste...

CVSS:8.3(High)

An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any prompts in any projects due to insufficient access control checks in the handling...

CVSS:8.6(High)

An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthentic...

CVSS:8.6(High)

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.

CVSS:8.6(High)

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVSS:8.6(High)

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.