VulnSea

CWE-115

CVEs classified under CWE-115, newest first.

5 CVEsRSS

CVE-2026-89671High· 7.0⚖ disputed
1w ago

kernel: nfsd: gate nfs3 setacl by argp->mask (CVE-2026-89671)

A flaw was found in the Linux kernel's Network File System version 3 (NFSv3) server daemon (`nfsd`). The `nfsd3_proc_setacl()` function unconditionally processes Access Control List (ACL) update requests, even when the client's request doe…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.49%via CSAF
CVE-2026-17566Critical· 9.9PoC
1mo ago

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the…

AbyssalEPSS 0.56%via NVD
CVE-2026-17351Critical· 9.0PoC
1mo ago

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TR…

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TR…

AbyssalEPSS 0.41%via NVD
GHSA-x8xr-mj9x-6h7wMedium· 4.8
3mo ago

Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

Sunlitvllm · vllmvia GHSA
CVE-2025-32908High· 7.5
1y ago

A flaw was found in libsoup

A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authority, and :path, which may allow a user to cause a denial of service (DoS).

TwilightEPSS 0.60%via NVD
CWE-115 vulnerabilities (CVEs) · VulnSea