VulnSea

CWE-187

CVEs classified under CWE-187, newest first.

5 CVEsRSS

CVE-2026-81479Medium· 5.8
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.

SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.23%via NVD
CVE-2026-87853High· 7.5
1w ago

A flaw was found in SSSD's IdP authentication provider

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of …

TwilightRed Hat · sssdEPSS 0.28%via NVD
CVE-2026-84376Medium
2w ago

Astro is a web framework for content-driven websites

Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a string-prefix check without verifying a path-segment boundary. With base "/app", a reques…

Sunlitastro · astroEPSS 0.41%via NVD
CVE-2026-62750Medium· 6.5
1mo ago

Windows HTTP Protocol Stack Tampering Vulnerability

Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.57%via CVEORG
CVE-2026-55602Medium
3mo ago

http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass

http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass

Sunlithttp-proxy-middleware · http-proxy-middlewareEPSS 0.37%via GHSA
CWE-187 vulnerabilities (CVEs) · VulnSea