VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

CVE-2026-55124Medium· 5.5
2mo ago

Microsoft Word Information Disclosure Vulnerability

Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.60%via CVEORG
CVE-2026-59955High· 7.5
2mo ago

Apollo ConfigService access key authentication bypass via raw config file appId parsing

Apollo ConfigService access key authentication bypass via raw config file appId parsing

▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
CVE-2026-59954High· 7.5
2mo ago

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching

▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
CVE-2026-15535Medium· 6.3
2mo ago

A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99

A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Exe…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-15531Medium· 5.3
2mo ago

A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706

A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the component Checkpoint File Handler. The manipu…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-15529Medium· 6.3
2mo ago

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The a…

▾ Sunlitpyod · pyodEPSS 0.44%via NVD
CVE-2026-3576High· 7.2PoC
2mo ago

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly acc…

▾ MidnightEPSS 8.8%via NVD
CVE-2026-49866High· 7.5
2mo ago

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

▾ Twilightlibp2p · @libp2p/gossipsubEPSS 0.63%via GHSA
CVE-2026-0282Medium· 6.5
2mo ago

A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this iss…

A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The security risk posed by this iss…

▾ Sunlitpaloaltonetworks · pan-osEPSS 0.29%via NVD
CVE-2026-59724High· 7.5
2mo ago

Socket.IO enables bidirectional and low-latency communication for every platform

Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of th…

▾ Twilightsocket · engine.ioEPSS 0.61%via NVD
CVE-2026-53513Critical· 9.6
2mo ago

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

▾ Midnightbetter-auth · @better-auth/ssoEPSS 0.25%via GHSA
CVE-2026-54234High· 7.5
2mo ago

vllm: vLLM: Denial of Service via malformed speculative decoding workload (CVE-2026-54234)

A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for Large Language Models (LLMs). A remote attacker can exploit this vulnerability by sending a specially crafted multi-request speculative decod…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.62%via CSAF
CVE-2026-35369Medium· 5.5
2mo ago

kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)

kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)

▾ Sunlituu_kill · uu_killEPSS 0.15%via GHSA
CVE-2026-35347Medium· 4.4
2mo ago

comm: FIFO/pipe inputs are drained before comparison (data loss / hang)

comm: FIFO/pipe inputs are drained before comparison (data loss / hang)

▾ Sunlituu_comm · uu_commEPSS 0.15%via GHSA
CVE-2026-57985High· 7.6
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.72%via CVEORG
CVE-2026-58292High· 7.5
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.48%via CVEORG
CVE-2026-22547None
2mo ago

Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.

Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or object format values.

▾ SunlitEPSS 0.52%via NVD
CVE-2026-14631Medium· 5.3
2mo ago

webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malf…

webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malf…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-13341High· 7.4
2mo ago

A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.

A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.

▾ TwilightEPSS 0.45%via NVD
CVE-2026-50196High· 7.5
2mo ago

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch

▾ TwilightSteeltoe · Steeltoe.Discovery.EurekaEPSS 0.61%via GHSA
GHSA-c8w6-x74f-vmg3Medium· 6.5
2mo ago

zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers

zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers

▾ Sunlitzebra-rpc · zebra-rpcvia GHSA
GHSA-77q5-rr5v-x43qHigh
2mo ago

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-14411Critical· 9.6
2mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-14401High· 8.3
2mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (C…

▾ Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-14382Critical· 9.6PoC
2mo ago

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 0.34%via NVD
CVE-2026-53492High· 8.2
2mo ago

github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint r…

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotat…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.35%via CSAF
CVE-2026-47198High· 8.5
2mo ago

Paymenter has URL parameter injection that bypasses paid plan limits at checkout

Paymenter has URL parameter injection that bypasses paid plan limits at checkout

▾ Twilightpaymenter · paymenter/paymenterEPSS 0.40%via GHSA
CVE-2026-49218High· 7.5
3mo ago

ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions

ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions

▾ TwilightMagick · Magick.NET-Q16-AnyCPUEPSS 0.63%via GHSA
GHSA-jj69-4grx-fqj5Critical· 7.8
3mo ago

Duplicate Advisory: Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses

Duplicate Advisory: Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses

▾ Midnightgoogle-github-actions · google-github-actions/run-gemini-clivia GHSA
CVE-2026-12537High· 7.8⚖ disputed
3mo ago

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …

▾ Twilightgoogle · gemini-cliEPSS 0.21%via NVD
CWE-20 vulnerabilities (CVEs) — page 14 · VulnSea