VulnSea

CWE-1188

CVEs classified under CWE-1188, newest first.

56 CVEsRSS

CVE-2026-54066High· 7.5PoC
2mo ago

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 2.4%via GHSA
CVE-2026-54067Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via GHSA
CVE-2026-54158Critical· 9.9
2mo ago

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.51%via GHSA
CVE-2026-14474High· 8.8
2mo ago

A flaw was found in SSSD's LDAP sudo provider

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subt…

▾ TwilightEPSS 0.82%via NVD
GHSA-9h47-pqcx-hjr4High· 8.7
2mo ago

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

▾ Twilightbetter-auth · better-authvia GHSA
CVE-2026-46386Critical· 9.9
3mo ago

OpenProject is open-source, web-based project management software

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :m…

▾ MidnightEPSS 0.49%via NVD
GHSA-9j7f-3r4p-pwh6Medium· 5.2
3mo ago

nono-py vulnerable to authorization bypass / policy confusion

nono-py vulnerable to authorization bypass / policy confusion

▾ Sunlitnono-py · nono-pyvia GHSA
CVE-2026-48502High
3mo ago

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

▾ TwilightMessagePack · MessagePackEPSS 0.44%via GHSA
CVE-2026-48509Medium
3mo ago

MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies

MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies

▾ SunlitMessagePack · MessagePackEPSS 0.42%via GHSA
CVE-2026-50519Medium· 6.5
3mo ago

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · github_copilot_chatEPSS 0.92%via NVD
GHSA-v52w-28xh-v562High
3mo ago

Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)

Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)

▾ Twilightkozou · kozouvia GHSA
GHSA-j4hj-7hfh-g2f4Critical· 9.8
3mo ago

praisonai: recipe serve auth middleware silently disables itself when no secret is set

praisonai: recipe serve auth middleware silently disables itself when no secret is set

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-j4f3-55x4-r6q2Critical· 9.8
3mo ago

npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call

npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-f38v-77qj-h4jqCritical· 9.8
3mo ago

praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)

praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)

▾ Midnightpraisonai-platform · praisonai-platformvia GHSA
GHSA-cwj8-7gp2-ggcwCritical· 9.8
3mo ago

praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery

praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery

▾ Midnightpraisonai-platform · praisonai-platformvia GHSA
CVE-2026-0134Medium· 4.0
3mo ago

In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code

In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User i…

▾ Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-40994High· 8.2
3mo ago

Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData

Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept…

▾ Twilightbroadcom · spring_web_servicesEPSS 0.34%via NVD
CVE-2026-44892High· 7.5
3mo ago

Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size

Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size

▾ Twilightnetty · io.netty:netty-codec-http3EPSS 0.49%via GHSA
CVE-2026-6866High· 7.5
4mo ago

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorize…

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorize…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-31818Critical· 9.6
5mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerability exists in Budibase's REST datasource connector. The platform's SSRF protection mechanism (IP blacklist) is rendered…

▾ Midnightbudibase · budibaseEPSS 0.43%via NVD
CVE-2026-24148High· 8.3
6mo ago

NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default

NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might…

▾ Twilightnvidia · jetson_linuxEPSS 0.35%via NVD
CVE-2025-24288Critical· 9.8
1y ago

The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials

The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Vers…

▾ Midnightversa-networks · versa_directorEPSS 0.47%via NVD
CVE-2022-2196Medium· 5.8
3y ago

A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) adv…

A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1 due to L1 thinking it doesn't need retpolines or IBPB after running L2 due to KVM (L0) adv…

▾ Sunlitlinux · linux_kernelEPSS 0.29%via NVD
CVE-2021-34203High· 8.1
5y ago

D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control

D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password…

▾ Twilightdlink · dir-2640-us_firmwareEPSS 1.2%via NVD
CVE-2017-8039Medium· 5.9
8y ago

An issue was discovered in Pivotal Spring Web Flow through 2.4.5

An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to m…

▾ Sunlitbroadcom · spring_web_flowEPSS 0.96%via NVD
CVE-2017-4971Medium· 5.9PoC
9y ago

An issue was discovered in Pivotal Spring Web Flow through 2.4.4

An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to m…

▾ Twilightbroadcom · spring_web_flowEPSS 15%via NVD
CWE-1188 vulnerabilities (CVEs) — page 2 · VulnSea