VulnSea

CWE-185

CVEs classified under CWE-185, newest first.

7 CVEsRSS

CVE-2026-54506High· 7.6
5d ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in sys…

Twilightgivanz · VvvebEPSS 0.25%via NVD
CVE-2026-88021High· 7.5
1w ago

Consul vulnerable to an authorization bypass in the Connect service mesh

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentio…

TwilightHashiCorp · ConsulEPSS 0.24%via CVEORG
CVE-2026-73425Low· 3.7
1mo ago

Astro is a web framework for content-driven websites

Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written to .netlify/v1/config.json under images.remote_images for Netlify'…

SunlitEPSS 0.17%via NVD
CVE-2026-64655None
1mo ago

GitHub CLI (gh) is GitHub’s official command line tool

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify  builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow  flag values without escaping regex meta…

SunlitEPSS 0.33%via NVD
GHSA-hp3v-mfqw-h74cLow· 3.7
2mo ago

@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped

@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped

Sunlitastrojs · @astrojs/netlifyvia GHSA
CVE-2026-48147Medium· 6.5
3mo ago

Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker

Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker

Sunlitbudibase · @budibase/backend-coreEPSS 0.11%via GHSA
CVE-2026-25896Critical· 9.3PoC⚖ disputed
7mo ago

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard…

Abyssalnaturalintelligence · fast-xml-parserEPSS 0.47%via NVD
CWE-185 vulnerabilities (CVEs) · VulnSea