VulnSea

CWE-1023

CVEs classified under CWE-1023, newest first.

10 CVEsRSS

CVE-2026-92611Medium· 4.8
5d ago

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entr…

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entr…

SunlitEclipse Foundation · Eclipse AnkaiosEPSS 0.21%via NVD
CVE-2026-91836Low· 2.8PoC
1w ago

A flaw has been found in OpenClaw ClawScan up to 0.1.6

A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. …

TwilightOpenClaw · ClawScanEPSS 0.31%via NVD
CVE-2026-54181Medium· 5.4
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/views/crud/columns…

SunlitLaravel-Backpack · CRUDEPSS 0.30%via NVD
CVE-2026-81376Critical· 9.6
2w ago

Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Midnightmicrosoft · visual_studio_codeEPSS 0.65%via NVD
CVE-2026-14199High· 7.1
2w ago

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a del…

Twilightgrafana · grafanaEPSS 0.31%via NVD
CVE-2026-54713Low· 3.7
3w ago

CakePHP Queue is a queue-interop compatible queueing library

CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers for jobs with shouldBeUnique enabled from the job class, method, and parameters, but sorting paramet…

Sunlitcakephp · cakephp/queueEPSS 0.36%via NVD
CVE-2026-24255High· 7.5
1mo ago

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successf…

Twilightnvidia · dynamoEPSS 0.38%via NVD
GHSA-77q5-rr5v-x43qHigh
2mo ago

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

Twilightopenclaw · openclawvia GHSA
CVE-2026-48761Medium
3mo ago

Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes

Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes

Sunlitsymfony · symfony/html-sanitizerEPSS 0.34%via GHSA
CVE-2026-4599Critical· 9.1
6mo ago

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker …

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker …

Midnightkjur · jsrsasignEPSS 0.48%via NVD
CWE-1023 vulnerabilities (CVEs) · VulnSea