CWE-1270
CVEs classified under CWE-1270, newest first.
2 CVEsRSS
CVE-2026-54593High· 8.1Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
▾ Twilightpterodactyl · pterodactyl/panelEPSS 0.36%via GHSA
CVE-2025-59698Medium· 6.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), might allow a physically proximate attacker to gain access to the EOL legacy bootloader.
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), might allow a physically proximate attacker to gain access to the EOL legacy bootloader.
▾ Sunlitentrust · nshield_5c_firmwareEPSS 0.33%via NVD