VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

CVE-2026-17663High· 8.3
1mo ago

Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr…

▾ Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-17651Critical· 9.6
1mo ago

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-17791Medium· 6.5
1mo ago

Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page

Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-17789Medium· 6.5
1mo ago

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Medium)

▾ SunlitEPSS 0.27%via NVD
CVE-2026-17768Critical· 9.6
1mo ago

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromiu…

▾ MidnightEPSS 0.34%via NVD
CVE-2026-17761Medium· 5.4
1mo ago

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: …

▾ SunlitEPSS 0.20%via NVD
CVE-2026-54663Medium· 6.1
2mo ago

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

▾ Sunlitswagger-typescript-api · swagger-typescript-apiEPSS 0.32%via GHSA
CVE-2026-62828Medium· 5.4
2mo ago

Microsoft Edge for Android (Chromium-based) Tampering Vulnerability

Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.

▾ SunlitMicrosoft · Microsoft Edge for AndroidEPSS 0.41%via CVEORG
CVE-2026-50569Medium· 4.3
2mo ago

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks

▾ Sunlitfission · github.com/fission/fissionEPSS 0.39%via GHSA
CVE-2026-54272High· 7.2
2mo ago

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifie…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v.9.6)EPSS 0.43%via NVD
GHSA-rjg6-39jm-rgg4Critical· 9.9
2mo ago

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

▾ Midnightbetter-auth · @better-auth/scimvia GHSA
CVE-2026-54120Critical· 9.9
2mo ago

Microsoft Surface Remote Code Execution Vulnerability

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

▾ MidnightMicrosoft · Surface Management ServicesEPSS 0.96%via CVEORG
GHSA-xmf8-cvqr-rfgjHigh· 7.5
2mo ago

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers

▾ Twilightauth · @auth/corevia GHSA
GHSA-9cmh-xcqm-5hqrMedium
2mo ago

n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner

n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-6790Medium· 5.3
2mo ago

Eclipse Jetty: HTTP Authority/Host mismatch

Eclipse Jetty: HTTP Authority/Host mismatch

▾ Sunliteclipse · org.eclipse.jetty:jetty-serverEPSS 0.31%via GHSA
CVE-2026-55554Low
2mo ago

Dompdf: Chroot Validation Bypass

Dompdf: Chroot Validation Bypass

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.45%via GHSA
CVE-2026-56722Medium
2mo ago

Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI

Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI

▾ Sunlitdompdf · dompdf/dompdfEPSS 0.45%via GHSA
CVE-2026-60613Medium· 6.6
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking)

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows high privileged atta…

▾ Sunlitoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.40%via NVD
CVE-2026-60603High· 8.8
2mo ago

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Australian Features)

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Australian Features). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attac…

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.43%via NVD
CVE-2026-60526Medium· 6.7
2mo ago

Vulnerability in Oracle Java SE (component: Installation)

Vulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u491 and 8u491-perf. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructur…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-16117Critical· 10.0
2mo ago

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encode…

▾ MidnightEPSS 0.44%via NVD
CVE-2026-50012Medium· 5.5
2mo ago

Squid is a caching proxy for the Web

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest'…

▾ Sunlitsquid-cache · squidEPSS 2.7%via NVD
CVE-2026-20153High· 7.5
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

▾ Twilightcisco · roomosEPSS 0.47%via NVD
GHSA-7gcf-g7xr-8hxjMedium
2mo ago

serde_with: KeyValueMap serialization panics on empty sequence or map entries

serde_with: KeyValueMap serialization panics on empty sequence or map entries

▾ Sunlitserde_with · serde_withvia GHSA
CVE-2026-52883Medium
2mo ago

MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs

MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs

▾ Sunlitmantisbt · mantisbt/mantisbtvia GHSA
CVE-2026-55899High· 7.8
2mo ago

Microsoft Excel Remote Code Execution Vulnerability

Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-50370High· 8.8
2mo ago

DHCP Server Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.50%via CVEORG
CVE-2026-50328High· 7.5
2mo ago

Windows Server Update Service (WSUS) Tampering Vulnerability

Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 1.2%via CVEORG
CVE-2026-50417High· 7.8
2mo ago

Windows NTFS Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50670High· 8.8
2mo ago

Windows Win32k Elevation of Privilege Vulnerability

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CWE-20 vulnerabilities (CVEs) — page 13 · VulnSea