VulnSea

CWE-180

CVEs classified under CWE-180, newest first.

14 CVEsRSS

CVE-2026-90813Medium· 4.3PoC
1w ago

A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13

A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in inc…

Twilightcosmicstack-labs · mercury-agentEPSS 0.31%via NVD
CVE-2026-79300Low· 3.5
1w ago

SEP sesam before 5.2.0.24 mishandles User Authorization with MFA

SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalizatio…

SunlitSEP · sesamEPSS 0.21%via NVD
CVE-2026-82481None
3w ago

The cohttp package before 6.3.0 for OCaml allows directory traversal.

The cohttp package before 6.3.0 for OCaml allows directory traversal.

SunlitEPSS 0.50%via NVD
CVE-2026-73420None
1mo ago

NextAuth.js provides authentication for Next.js

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before applying Unicode normali…

SunlitEPSS 0.53%via NVD
CVE-2026-73416Medium
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, Jup…

Sunlitjupyterlab · jupyterlabEPSS 0.49%via NVD
CVE-2026-72917Medium· 5.9
1mo ago

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/PasswordRecovery/index.…

SunlitEPSS 0.27%via NVD
CVE-2026-69245Medium· 6.5
1mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric hos…

Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.14%via NVD
CVE-2026-69246High· 7.2
1mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that H…

Twilightguzzlehttp · guzzlehttp/guzzleEPSS 0.21%via NVD
CVE-2026-62999High· 7.5PoC
1mo ago

Copier is a library and CLI app for rendering project templates

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an…

Midnightcopier-org · copierEPSS 0.37%via NVD
CVE-2026-7120Medium· 5.3
2mo ago

@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths

@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths

Sunlitfastify · @fastify/staticEPSS 0.37%via GHSA
GHSA-7rqj-j65f-68whCritical
2mo ago

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass

Midnightauth · @auth/corevia GHSA
GHSA-89vp-jrxv-24w8Medium
2mo ago

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

Sunlitjupyterlab · jupyterlabvia GHSA
CVE-2026-52747High· 8.6
2mo ago

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-…

TwilightEPSS 0.48%via NVD
CVE-2026-39364High· 7.5PoC
5mo ago

Vite is a frontend tooling framework for JavaScript

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query par…

Midnightvitejs · viteEPSS 2.0%via NVD
CWE-180 vulnerabilities (CVEs) · VulnSea