VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

CVE-2026-84504High· 8.1
3w ago

fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers

fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at th…

▾ Twilightfastify · fastifyEPSS 0.43%via NVD
CVE-2026-84469High· 7.5
3w ago

fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance

fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false …

▾ Twilightfastify · fastifyEPSS 0.49%via NVD
CVE-2026-50553High
3w ago

Note Mark is an open-source note-taking application

Note Mark is an open-source note-taking application. Prior to version 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma tag pattern:"[a-z0-9-]+". huma compiles this with regexp.MustCompile(s.Pattern) and tests i…

▾ Twilightenchant97 · github.com/enchant97/note-mark/backendEPSS 0.46%via NVD
CVE-2026-85239Medium· 6.5
3w ago

A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only p…

A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only p…

▾ Sunlitmisp-project · mispEPSS 0.45%via NVD
CVE-2026-85230Medium· 5.4
3w ago

A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration

A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were not validated when the configuration was saved. As a…

▾ Sunlitmisp-project · mispEPSS 0.29%via NVD
CVE-2026-85170Medium· 6.5
3w ago

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string

n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is a string. An authenticated user able to run a workflow can supply an expression that res…

▾ Sunlitn8n · n8nEPSS 0.40%via NVD
CVE-2026-85047Critical· 9.6
3w ago

Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity…

▾ Midnightgoogle · chromeEPSS 0.46%via NVD
CVE-2026-18504Medium· 5.4PoC
3w ago

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

▾ Twilightfastify · fastifyEPSS 0.31%via GHSA
CVE-2026-53600Medium
3w ago

async-tar is a tar archive reading/writing library for async Rust

async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g header) …

▾ Sunlitasync-tar · async-tarEPSS 0.45%via NVD
CVE-2026-49830Medium· 4.4
3w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting an aggregated ORE resource by URI (using the OAI-ORE Harvester), the …

▾ Sunlitdspace · org.dspace:dspace-apiEPSS 0.49%via NVD
CVE-2026-84325Critical· 9.8
3w ago

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app

Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

▾ MidnightGoogle · ChromeEPSS 0.40%via CVEORG
CVE-2026-84357Medium· 6.5
3w ago

Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic

Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)

▾ SunlitGoogle · ChromeEPSS 0.27%via CVEORG
CVE-2026-83492None
3w ago

Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1.

Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-81633None
4w ago

Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id: ...) query with an unhandled KeyError. AshGraphql.Graphql.Resolver.resolve_node/2 decodes the client-supplied …

Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id: ...) query with an unhandled KeyError. AshGraphql.Graphql.Resolver.resolve_node/2 decodes the client-supplied …

▾ SunlitEPSS 0.52%via NVD
CVE-2026-82550Medium· 5.3
4w ago

A security flaw has been discovered in Linux Foundation Magma 1.9.0

A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input va…

▾ SunlitEPSS 0.70%via NVD
CVE-2026-82648High· 7.1
4w ago

WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form

WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-enco…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-82639High· 7.5PoC
4w ago

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key

NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching …

▾ MidnightChatGPTNextWeb · NextChatEPSS 0.51%via NVD
CVE-2026-55068Critical
1mo ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum va…

▾ Midnightfree5gc · github.com/free5gc/free5gcEPSS 0.59%via NVD
CVE-2026-81707Critical· 9.8
1mo ago

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a cr…

▾ MidnightEPSS 0.59%via NVD
CVE-2026-47880Medium· 5.4
1mo ago

A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integrat…

A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integrat…

▾ Sunlitvmware · spring_integrationEPSS 0.26%via NVD
CVE-2026-57499Critical· 9.1
1mo ago

Liman is open source server management software

Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands…

▾ MidnightEPSS 1.4%via NVD
CVE-2026-35869Critical· 9.8
1mo ago

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before i…

▾ MidnightEPSS 2.3%via NVD
CVE-2026-35868Critical· 9.8
1mo ago

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input befo…

▾ MidnightEPSS 2.3%via NVD
CVE-2026-59322Medium· 6.3
1mo ago

The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor

The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-54718High· 7.2
1mo ago

Silverstripe Advanced Workflow is a highly configurable step-based workflow module

Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side te…

▾ Twilightsymbiote · symbiote/silverstripe-advancedworkflowEPSS 1.0%via NVD
CVE-2026-54721High· 8.8
1mo ago

Silverstripe UserForms provides a visual form builder for the Silverstripe CMS

Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted a…

▾ Twilightsilverstripe · silverstripe/userformsEPSS 0.73%via NVD
CVE-2026-79000Medium· 4.3
1mo ago

Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic

Improper input validation in DeviceBoundSessionCredentials in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severi…

▾ SunlitGoogle · ChromeEPSS 0.25%via CVEORG
CVE-2026-78976Medium· 4.3
1mo ago

Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page

Improper input validation in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Me…

▾ SunlitGoogle · ChromeEPSS 0.27%via CVEORG
CVE-2026-79192Medium· 4.3
1mo ago

Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via crafted network traffic

Improper input validation in Variations in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.25%via CVEORG
CVE-2026-79151Medium· 6.5⚖ disputed
1mo ago

chromium-browser: Chromium-browser Safebrowsing: Bypass system access restrictions via improper input validation. (CVE-2026-79151)

A flaw was found in Chromium-browser's Safebrowsing component. A remote attacker could exploit this vulnerability by providing a specially crafted file. This could allow the attacker to bypass system access restrictions.

▾ SunlitRed Hat · ChromeEPSS 0.23%via CSAF
CWE-20 vulnerabilities (CVEs) — page 8 · VulnSea