VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

CVE-2026-62917Medium· 4.6
1mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-71217High· 7.5PoC
1mo ago

A flaw was found in iperf3

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This im…

▾ MidnightEPSS 0.82%via NVD
CVE-2026-9214Medium· 4.5
1mo ago

Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

▾ Sunlitnetgear · r7000_firmwareEPSS 0.23%via NVD
CVE-2026-11738Medium· 4.4
1mo ago

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

▾ Sunlitnetgear · be9300_firmwareEPSS 0.27%via NVD
CVE-2026-11737Medium· 4.5
1mo ago

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.

Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.

▾ Sunlitnetgear · rax20_firmwareEPSS 0.22%via NVD
CVE-2026-11736Medium· 4.9
1mo ago

A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.

A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.

▾ Sunlitnetgear · rax20_firmwareEPSS 0.51%via NVD
CVE-2026-61363High· 7.5
1mo ago

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.68%via NVD
CVE-2026-59134High· 7.5
1mo ago

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.68%via NVD
CVE-2026-72867Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-2026-45628 leaves packages/server/src/db/schema/compose.ts branch fields without server-side validation, allowing a dire…

▾ MidnightEPSS 0.95%via NVD
CVE-2026-72728Medium· 6.3
1mo ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox allowlist and embedded malicious content in a site. This issue is fixed in versions 202…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-19363Medium· 5.3
1mo ago

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is the function unwrap of the file src/handler.rs of the component Fixed Message Handler. The manipulation of the argument jwtClaims results in deserialization. …

▾ SunlitEPSS 0.67%via NVD
CVE-2026-62295High· 7.5PoC
1mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arra…

▾ Midnighthapifhir · org.hl7.fhir.coreEPSS 0.49%via NVD
CVE-2026-62296High· 7.5
1mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded…

▾ TwilightRed Hat · Red Hat build of Apache Camel 4 for Quarkus 3EPSS 0.49%via NVD
CVE-2026-62293Medium· 5.0
1mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command concatenates attacker-controlled Implementation Guide titles, profile titles, and source re…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-47664None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, the `$import-pnp` operation in Pathling Server accepts a caller-supplied `export…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-47662None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR surface allows an authenticated caller w…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-50540Critical· 9.6
1mo ago

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalida…

▾ MidnightEPSS 0.61%via NVD
CVE-2024-10302Medium· 4.0
1mo ago

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input

The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowi…

▾ Sunlitwso2 · api_control_planeEPSS 0.29%via NVD
CVE-2026-19164Critical· 9.6
1mo ago

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-19143High· 8.6
1mo ago

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.13%via NVD
CVE-2026-46334None
1mo ago

OpenSIPS is a Session Initiation Protocol (SIP) server implementation

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/…

▾ SunlitEPSS 0.67%via NVD
CVE-2026-20303Critical· 9.9PoC
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

▾ AbyssalEPSS 0.49%via NVD
CVE-2026-20273High· 8.6
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that…

▾ TwilightCisco · Cisco IOS XE SoftwareEPSS 0.47%via NVD
CVE-2026-71318Medium· 4.8
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through <component :is>,…

▾ Sunlitnuxt · nuxtEPSS 0.32%via NVD
CVE-2026-70603Medium· 6.0
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that p…

▾ Sunlitelectron · electronEPSS 0.14%via NVD
CVE-2026-70607Medium· 5.3
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied by web content in the window.open() features string …

▾ Sunlitelectron · electronEPSS 0.58%via NVD
CVE-2026-70589Medium· 4.8
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.

▾ Sunlitghost · ghostEPSS 0.27%via NVD
CVE-2026-21555High· 7.5
1mo ago

In modem, there is a possible improper input validation

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

▾ TwilightEPSS 0.71%via NVD
CVE-2026-21554High· 7.5
1mo ago

In modem, there is a possible improper input validation

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

▾ TwilightEPSS 0.71%via NVD
CVE-2026-21553High· 7.5
1mo ago

In modem, there is a possible improper input validation

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

▾ TwilightEPSS 0.71%via NVD
CWE-20 vulnerabilities (CVEs) — page 11 · VulnSea