CWE-20
CVEs classified under CWE-20, newest first.
655 CVEsRSS
GHSA-55cm-p4ww-685gMedium· 5.3Duplicate Advisory: Hono missing validation of cookie name on write path in setCookie()
Duplicate Advisory: Hono missing validation of cookie name on write path in setCookie()
CVE-2026-10651High· 7.1A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser
A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser. In subsys/bluetooth/host/classic/sdp.c, bt_sdp_parse_attribute() accepts an input buffer once it contains the 1-byte attribute type and…
CVE-2026-52801High· 8.1Gogs has the ability to import local repositories via Mirror Settings
Gogs has the ability to import local repositories via Mirror Settings
CVE-2025-64719Medium· 4.9Gogs has a Denial of Service in repository/wiki file listing web pages
Gogs has a Denial of Service in repository/wiki file listing web pages
CVE-2026-21887High· 7.7OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
CVE-2026-33692High· 7.5AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration
AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration
CVE-2026-56340High· 8.8vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing
vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with mal…
GHSA-78fp-cf4h-g36pHigh· 8.8Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164
Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164
CVE-2026-49208Mediumux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
CVE-2026-54911Medium· 6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
GHSA-78vr-q6cf-c7p6MediumCraft Commerce: Partial Payment Amount Without Lower Bound Validation
Craft Commerce: Partial Payment Amount Without Lower Bound Validation
CVE-2026-12569Critical· 9.8CISA KEVA critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS…
CVE-2026-55602Mediumhttp-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
GHSA-38x9-25wx-7fg2HighHeimdall: IP Spoofing via Unvalidated Forwarding Headers
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
GHSA-4jgr-pg2m-m988HighHeimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
GHSA-c969-5x3p-vq3vHigh· 8.1PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
GHSA-4pcv-mg8v-vrgfHigh· 8.8PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
CVE-2026-12566Low· 3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
CVE-2026-54319Medium· 4.2Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
CVE-2026-53859Medium· 6.5OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
CVE-2026-0142Medium· 4.0In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation
In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed …
CVE-2026-54299High· 7.5Astro: Host header SSRF in prerendered error page fetch
Astro: Host header SSRF in prerendered error page fetch
CVE-2026-49444High· 8.5n8n: Python sandbox escape
n8n: Python sandbox escape
CVE-2026-49982High· 8.2tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template
CVE-2026-53537Low· 3.7python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
CVE-2026-54282Low· 3.7Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
CVE-2026-54133Critical· 9.8jmespath.php: jmespath.php has CompilerRuntime code injection via unescaped function names (CVE-2026-54133)
A flaw was found in jmespath.php, a library for processing JSON documents in PHP applications. This vulnerability allows a remote attacker to execute arbitrary code by crafting a malicious JMESPath expression. The `JmesPath\CompilerRuntime…
CVE-2026-50633High· 8.1A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. …
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. …
CVE-2026-50632High· 8.1A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…
CVE-2026-50628Critical· 9.8A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security c…