VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

GHSA-55cm-p4ww-685gMedium· 5.3
3mo ago

Duplicate Advisory: Hono missing validation of cookie name on write path in setCookie()

Duplicate Advisory: Hono missing validation of cookie name on write path in setCookie()

▾ Sunlithono · honovia GHSA
CVE-2026-10651High· 7.1
3mo ago

A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser

A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser. In subsys/bluetooth/host/classic/sdp.c, bt_sdp_parse_attribute() accepts an input buffer once it contains the 1-byte attribute type and…

▾ Twilightzephyrproject · zephyrEPSS 0.30%via NVD
CVE-2026-52801High· 8.1
3mo ago

Gogs has the ability to import local repositories via Mirror Settings

Gogs has the ability to import local repositories via Mirror Settings

▾ Twilightgogs · gogs.io/gogsEPSS 0.57%via GHSA
CVE-2025-64719Medium· 4.9
3mo ago

Gogs has a Denial of Service in repository/wiki file listing web pages

Gogs has a Denial of Service in repository/wiki file listing web pages

▾ Sunlitgogs · gogs.io/gogsEPSS 0.44%via GHSA
CVE-2026-21887High· 7.7
3mo ago

OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature

OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature

▾ Twilightpycti · pyctiEPSS 0.21%via GHSA
CVE-2026-33692High· 7.5
3mo ago

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

▾ Twilightwwbn · wwbn/avideoEPSS 0.45%via GHSA
CVE-2026-56340High· 8.8
3mo ago

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with mal…

▾ Twilightvllm · vllmEPSS 0.64%via NVD
GHSA-78fp-cf4h-g36pHigh· 8.8
3mo ago

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

Duplicate Advisory: vLLM introduced enhanced protection for CVE-2025-62164

▾ Twilightvllm · vllmvia GHSA
CVE-2026-49208Medium
3mo ago

ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor

ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.41%via GHSA
CVE-2026-54911Medium· 6.5
3mo ago

UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()

UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()

▾ Sunlitujson · ujsonEPSS 0.37%via OSV
GHSA-78vr-q6cf-c7p6Medium
3mo ago

Craft Commerce: Partial Payment Amount Without Lower Bound Validation

Craft Commerce: Partial Payment Amount Without Lower Bound Validation

▾ Sunlitcraftcms · craftcms/commercevia GHSA
CVE-2026-12569Critical· 9.8CISA KEV
3mo ago

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS…

▾ Hadalptc · flexplmEPSS 46%via NVD
CVE-2026-55602Medium
3mo ago

http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass

http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass

▾ Sunlithttp-proxy-middleware · http-proxy-middlewareEPSS 0.38%via GHSA
GHSA-38x9-25wx-7fg2High
3mo ago

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

▾ Twilighthttps: · https://github.com/dadrus/heimdallvia GHSA
GHSA-4jgr-pg2m-m988High
3mo ago

Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode

Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode

▾ Twilightdadrus · github.com/dadrus/heimdallvia GHSA
GHSA-c969-5x3p-vq3vHigh· 8.1
3mo ago

PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters

PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters

▾ Twilightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-4pcv-mg8v-vrgfHigh· 8.8
3mo ago

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

▾ Twilightpraisonaiagents · praisonaiagentsvia GHSA
CVE-2026-12566Low· 3.1
3mo ago

BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing

BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing

▾ Sunlitbbot · bbotEPSS 0.17%via GHSA
CVE-2026-54319Medium· 4.2
3mo ago

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape

▾ Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.24%via GHSA
CVE-2026-53859Medium· 6.5
3mo ago

OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently

OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently

▾ Sunlitopenclaw · openclawEPSS 0.36%via GHSA
CVE-2026-0142Medium· 4.0
3mo ago

In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation

In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed …

▾ Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-54299High· 7.5
3mo ago

Astro: Host header SSRF in prerendered error page fetch

Astro: Host header SSRF in prerendered error page fetch

▾ Twilightastro · astroEPSS 0.33%via GHSA
CVE-2026-49444High· 8.5
3mo ago

n8n: Python sandbox escape

n8n: Python sandbox escape

▾ Twilightn8n · n8nEPSS 0.39%via GHSA
CVE-2026-49982High· 8.2
3mo ago

tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template

tmp: Type-confusion bypass of _assertPath allows path traversal via non-string prefix/postfix/template

▾ Twilighttmp · tmpEPSS 0.60%via GHSA
CVE-2026-53537Low· 3.7
3mo ago

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

▾ Sunlitpython-multipart · python-multipartEPSS 0.29%via OSV
CVE-2026-54282Low· 3.7
3mo ago

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

▾ Sunlitstarlette · starletteEPSS 0.27%via OSV
CVE-2026-54133Critical· 9.8
3mo ago

jmespath.php: jmespath.php has CompilerRuntime code injection via unescaped function names (CVE-2026-54133)

A flaw was found in jmespath.php, a library for processing JSON documents in PHP applications. This vulnerability allows a remote attacker to execute arbitrary code by crafting a malicious JMESPath expression. The `JmesPath\CompilerRuntime…

▾ MidnightRed Hat · mtdowling/jmespath.phpEPSS 0.56%via CSAF
CVE-2026-50633High· 8.1
3mo ago

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. …

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. …

▾ Twilightapache · cxfEPSS 1.3%via NVD
CVE-2026-50632High· 8.1
3mo ago

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JM…

▾ Twilightapache · cxfEPSS 1.1%via NVD
CVE-2026-50628Critical· 9.8
3mo ago

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security c…

▾ Midnightapache · cxfEPSS 1.0%via NVD
CWE-20 vulnerabilities (CVEs) — page 15 · VulnSea