VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

CVE-2026-3294High· 8.8
4mo ago

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Suc…

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator password due to insufficient validation. Suc…

▾ Twilighttp-link · re305_firmwareEPSS 0.57%via NVD
CVE-2026-20240Medium· 6.5
4mo ago

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not ho…

In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.2603.1, 10.3.2512.9, 10.2.2510.11, 10.1.2507.21, 10.0.2503.13, and 9.3.2411.129, a low-privileged user that does not ho…

▾ Sunlitsplunk · splunkEPSS 0.40%via NVD
CVE-2026-5946High· 7.5
4mo ago

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

▾ Twilightisc · bindEPSS 1.7%via NVD
CVE-2026-20685Medium· 6.5PoC
4mo ago

An attacker in a privileged network position may be able to leak sensitive information

An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue is fixed in PCC Release 5E290.3.

▾ Twilightapple · private_cloud_computeEPSS 0.27%via NVD
CVE-2026-20224High· 8.6PoC
4mo ago

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have va…

▾ MidnightEPSS 1.0%via NVD
CVE-2026-0238Low· 3.2
4mo ago

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

▾ Sunlitpaloaltonetworks · broker_vmEPSS 0.10%via NVD
CVE-2026-42579High· 7.5PoC
4mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding. This creates a bidirec…

▾ Midnightnetty · nettyEPSS 0.85%via NVD
CVE-2026-41293High· 7.3PoC⚖ disputed
4mo ago

tomcat-coyote: Apache Tomcat: HTTP/2 request headers not validated (CVE-2026-41293)

Apache Tomcat did not validate HTTP/2 request headers, triggering unexpected application behavior, as applications may presume that header values exposed through the Servlet API would be valid.

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream EUS (v. 10.0)EPSS 1.7%via CSAF
CVE-2026-34669Medium· 6.2
4mo ago

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to c…

▾ Sunlitadobe · c2paEPSS 0.27%via NVD
CVE-2026-34668Medium· 6.2
4mo ago

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to c…

▾ Sunlitadobe · c2paEPSS 0.27%via NVD
CVE-2026-34666Medium· 6.2
4mo ago

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service

CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to c…

▾ Sunlitadobe · c2paEPSS 0.27%via NVD
CVE-2025-35990High· 8.8
4mo ago

Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege

Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated us…

▾ Twilightintel · endpoint_management_assistantEPSS 0.22%via NVD
CVE-2026-28936High· 7.5
4mo ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.7, macOS Sonoma 14.8.8, macOS Tahoe 26.5, visionOS 26.5. Processing a ma…

▾ Twilightapple · ipadosEPSS 0.51%via NVD
CVE-2025-14576High· 7.8
5mo ago

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than nat…

▾ Twilightqt · qtdeclarativeEPSS 0.22%via NVD
CVE-2024-54011Medium· 6.5
5mo ago

Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data supplied in certain requests, causing a service disruption

Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data supplied in certain requests, causing a service disruption. The manufacturer has released patch firmware for the flaw, p…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-21733High· 7.3
5mo ago

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files. This is caused by improper handling of GPU memory reservation protecti…

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files. This is caused by improper handling of GPU memory reservation protecti…

▾ TwilightEPSS 0.10%via NVD
CVE-2026-26154High· 7.5
5mo ago

Windows Server Update Service (WSUS) Tampering Vulnerability

Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

▾ TwilightMicrosoft · Windows Server 2012EPSS 1.2%via CVEORG
CVE-2026-26161High· 7.8
5mo ago

Windows Sensor Data Service Elevation of Privilege Vulnerability

Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.33%via CVEORG
CVE-2026-27906Medium· 4.4
5mo ago

Windows Hello Security Feature Bypass Vulnerability

Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.41%via CVEORG
CVE-2026-32168High· 7.8
5mo ago

Azure Monitor Agent Elevation of Privilege Vulnerability

Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Azure MonitorEPSS 0.33%via CVEORG
CVE-2026-33826High· 8.0PoC
5mo ago

Windows Active Directory Remote Code Execution Vulnerability

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.

▾ MidnightMicrosoft · Windows Server 2012 R2EPSS 0.54%via CVEORG
CVE-2026-26143High· 7.8
5mo ago

Microsoft PowerShell Security Feature Bypass Vulnerability

Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

▾ TwilightMicrosoft · PowerShell 7.4EPSS 0.47%via CVEORG
CVE-2026-26156High· 7.8
5mo ago

Windows Hyper-V Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-26170High· 7.8
5mo ago

PowerShell Elevation of Privilege Vulnerability

Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-27913High· 7.7
5mo ago

Windows BitLocker Security Feature Bypass Vulnerability

Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.

▾ TwilightMicrosoft · Windows Server 2012EPSS 0.37%via CVEORG
CVE-2026-27928High· 8.7
5mo ago

Windows Hello Security Feature Bypass Vulnerability

Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · Windows Server 2016EPSS 0.71%via CVEORG
CVE-2026-32149High· 7.3
5mo ago

Windows Hyper-V Remote Code Execution Vulnerability

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.43%via CVEORG
CVE-2026-32201Medium· 6.5CISA KEV0dayPoC
5mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ MidnightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 0.98%via CVEORG
CVE-2026-32203High· 7.5
5mo ago

.NET and Visual Studio Denial of Service Vulnerability

Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 2.4%via CVEORG
CVE-2026-27299Medium· 6.3
5mo ago

Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read

Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could leverage this vulnerability to access sensitive files or data on the…

▾ Sunlitadobe · framemakerEPSS 0.26%via NVD
CWE-20 vulnerabilities (CVEs) — page 17 · VulnSea