VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

CVE-2026-84538Medium· 6.5
1w ago

A denial-of-service issue was addressed with improved input validation

A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service.

▾ Sunlitapple · macosEPSS 0.50%via NVD
CVE-2026-28960High· 7.5
1w ago

A denial-of-service issue was addressed with improved validation

A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. A remote attacker may be able to cause a denial-of-service.

▾ Twilightapple · ipadosEPSS 0.51%via NVD
CVE-2026-19543Medium· 6.2
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can m…

▾ SunlitIBM · Common LicensingEPSS 0.12%via NVD
GHSA-2xmm-m4wv-3fjhLow· 3.9
1w ago

October CMS: Incomplete Scheme Validation in Image Resizer

October CMS: Incomplete Scheme Validation in Image Resizer

▾ Sunlitoctober · october/octobervia GHSA
CVE-2026-90614Medium· 6.3
1w ago

A weakness has been identified in FedML-AI FedML up to 0.9.6

A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backen…

▾ SunlitFedML-AI · FedMLEPSS 0.43%via NVD
CVE-2026-59570High· 7.5
1w ago

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

▾ TwilightZscaler · Client ConnectorEPSS 0.13%via NVD
CVE-2026-59569High· 8.1
1w ago

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

▾ TwilightZscaler · Client ConnectorEPSS 0.18%via NVD
CVE-2026-90961Critical· 9.3
1w ago

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() inp…

▾ MidnightMISP · MISPEPSS 0.64%via NVD
CVE-2026-82441Critical· 9.1
1w ago

Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs

Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of their contents on t…

▾ MidnightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.27%via NVD
CVE-2026-54529Medium· 5.3
1w ago

SQLAdmin is a flexible Admin interface for SQLAlchemy models

SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker-controlled sortBy list-view query parameter without enforcing the configured column_sortable_l…

▾ Sunlitsmithyhq · sqladminEPSS 0.38%via NVD
CVE-2026-54182High· 8.1
1w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::mak…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.78%via NVD
CVE-2026-55072High· 8.5PoC
1w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/Dat…

▾ Midnightpimcore · pimcoreEPSS 0.41%via NVD
CVE-2026-54632High· 7.5
1w ago

SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET

SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted b…

▾ Twilightsipsorcery-org · sipsorceryEPSS 0.72%via NVD
CVE-2026-57130High· 8.1PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteri…

▾ MidnightMervinPraison · praisonaiagentsEPSS 0.46%via NVD
CVE-2026-53713Critical· 9.1
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not col…

▾ Midnightenvoyproxy · gatewayEPSS 0.43%via NVD
CVE-2026-90490Medium· 6.3PoC
2w ago

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remot…

▾ Twilightlenve · vhrEPSS 0.41%via NVD
CVE-2026-90575Low· 3.7PoC
2w ago

A weakness has been identified in PHPGurukul Small CRM 4.0

A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. I…

▾ TwilightPHPGurukul · Small CRMEPSS 0.48%via NVD
CVE-2026-85979High· 8.6
2w ago

Affected versions of Puppet Enterprise contain a command injection vulnerability

Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, …

▾ TwilightPerforce Software · Puppet EnterpriseEPSS 1.3%via NVD
CVE-2026-3096Medium· 4.7
2w ago

The product's web portals allow external links to be opened in a new browser tab

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navig…

▾ SunlitWSO2 · WSO2 API Control PlaneEPSS 0.29%via NVD
CVE-2026-13745High· 7.7
2w ago

A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory

A vulnerability in the Gemini CLI prior to version 0.39.1 allows attackers to achieve arbitrary code execution by tricking a victim into starting the CLI within an untrusted directory. The vulnerability is triggered via untrusted .env fi…

▾ TwilightGoogle Cloud · Gemini CLIEPSS 0.38%via NVD
CVE-2023-54393High· 7.5
2w ago

PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency

PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency. Attackers can send malformed JSON structures in LoginPacket to crash the …

▾ Twilightpmmp · PocketMine-MPEPSS 0.35%via NVD
CVE-2024-58380Medium· 6.5
2w ago

PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided

PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided. Attackers can send a crafted BookEditPacket with an inven…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.38%via NVD
CVE-2026-21112Medium· 5.5
2w ago

Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege

Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.

▾ Sunlitsamsung · androidEPSS 0.09%via NVD
CVE-2025-71417Medium· 6.5
2w ago

PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions

PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple co…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.31%via NVD
CVE-2026-54694Critical· 9.6PoC
2w ago

SkillTree is a micro-learning gamification platform

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` b…

▾ AbyssalNationalSecurityAgency · skills-serviceEPSS 0.47%via NVD
CVE-2026-21089High· 7.8
2w ago

Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

▾ Twilightsamsung · androidEPSS 0.10%via NVD
CVE-2026-21094High· 8.8⚖ disputed
2w ago

Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.

Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.

▾ Twilightsamsung · androidEPSS 0.16%via NVD
CVE-2026-21088High· 7.8
2w ago

Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

▾ Twilightsamsung · androidEPSS 0.11%via NVD
CVE-2026-86768Medium· 5.4PoC
2w ago

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, compo…

▾ Twilightsnipeitapp · snipe-itEPSS 0.35%via NVD
CVE-2026-21101High· 8.4
2w ago

Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.

Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.

▾ TwilightSamsung Mobile · Samsung Mobile DevicesEPSS 0.12%via CVEORG
CWE-20 vulnerabilities (CVEs) — page 5 · VulnSea