VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

GHSA-9r4w-jg96-92mvMedium· 6.8
3mo ago

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()

Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()

▾ Sunlitgoogle · github.com/google/go-attestationvia GHSA
CVE-2025-58175Medium· 6.5
3mo ago

GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution

GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution

▾ Sunlitgeoserver · org.geoserver.web:gs-web-appEPSS 0.47%via GHSA
CVE-2026-53999High· 7.7
3mo ago

Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)

Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)

▾ Twilightradius-project · github.com/radius-project/radiusvia GHSA
GHSA-ch3q-cw5r-f4hgMedium
3mo ago

ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation

ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation

▾ Sunlitconnectbot · org.connectbot.sshlib:sshlibvia GHSA
CVE-2026-49214Medium· 5.3
3mo ago

guzzlehttp/psr7 has CRLF Injection via URI Host Component

guzzlehttp/psr7 has CRLF Injection via URI Host Component

▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.31%via GHSA
CVE-2026-48998Medium· 5.3
3mo ago

guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation

guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation

▾ Sunlitguzzlehttp · guzzlehttp/psr7EPSS 0.31%via GHSA
CVE-2026-53723Medium· 5.8
3mo ago

guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator

guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator

▾ Sunlitguzzlehttp · guzzlehttp/guzzle-servicesEPSS 0.35%via GHSA
CVE-2026-48107Medium· 6.5
3mo ago

Russh: Unchecked keyboard-interactive prompt count in client auth path

Russh: Unchecked keyboard-interactive prompt count in client auth path

▾ Sunlitrussh · russhEPSS 0.42%via GHSA
CVE-2026-48108Medium· 5.3
3mo ago

Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input

Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input

▾ Sunlitrussh · russhEPSS 0.47%via GHSA
CVE-2026-48110High· 7.5
3mo ago

Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds

Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds

▾ Twilightrussh · russhEPSS 0.46%via GHSA
CVE-2026-48109High· 8.2
3mo ago

MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input

MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input

▾ TwilightMessagePack · MessagePackEPSS 0.51%via GHSA
CVE-2026-41727Medium· 6.5
3mo ago

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt coun…

▾ Sunlitvmware · spring_for_apache_kafkaEPSS 0.42%via NVD
CVE-2026-45642Low· 3.9
3mo ago

Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.37%via CVEORG
CVE-2026-47641Medium· 4.6
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.58%via CVEORG
CVE-2026-40376High· 7.5
3mo ago

Visual Studio Code Elevation of Privilege Vulnerability

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Visual Studio CodeEPSS 0.68%via CVEORG
CVE-2026-45636High· 7.8
3mo ago

Windows NTFS Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-48569High· 7.1
3mo ago

Visual Studio Code Security Feature Bypass Vulnerability

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

▾ TwilightMicrosoft · Visual Studio CodeEPSS 0.41%via CVEORG
CVE-2026-44811High· 7.8
3mo ago

Windows DWM Core Library Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 26H1EPSS 0.33%via CVEORG
CVE-2026-47931High· 8.4
3mo ago

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit t…

▾ Twilightadobe · coldfusionEPSS 0.47%via NVD
CVE-2026-47928Critical· 9.6
3mo ago

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an adm…

▾ Midnightadobe · coldfusionEPSS 0.49%via NVD
CVE-2026-47767Medium
3mo ago

SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

▾ Sunlitsymfony · symfony/runtimeEPSS 0.72%via GHSA
CVE-2026-47430Critical
3mo ago

Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.

Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.

▾ Midnightcordova-plugin-inappbrowser · cordova-plugin-inappbrowserEPSS 0.77%via GHSA
CVE-2026-49234High· 7.5
3mo ago

Routinator crashes when sending a maliciously crafted select-asn query parameter

Routinator crashes when sending a maliciously crafted select-asn query parameter

▾ Twilightroutinator · routinatorEPSS 0.33%via GHSA
CVE-2026-35081High· 8.1
3mo ago

The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.

The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.

▾ Twilightmbs-solutions · universal_gateway_firmwareEPSS 0.53%via NVD
CVE-2026-0085Medium· 5.5
3mo ago

In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation

In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User i…

▾ Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-0078High· 7.8
3mo ago

In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation

In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User inter…

▾ Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-46243High· 7.1PoC
3mo ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that …

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that …

▾ Midnightlinux · linux_kernelEPSS 0.20%via NVD
CVE-2026-45628Critical· 9.6
4mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them via child_process.exec() (which runs through /bin/sh -c). User-s…

▾ MidnightEPSS 0.39%via NVD
CVE-2026-40411Critical· 9.9
4mo ago

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

▾ Midnightmicrosoft · azure_virtual_network_gatewayEPSS 0.96%via NVD
CVE-2026-26147High· 7.7
4mo ago

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

▾ Twilightmicrosoft · azure_stack_hciEPSS 1.0%via NVD
CWE-20 vulnerabilities (CVEs) — page 16 · VulnSea