VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

655 CVEsRSS

CVE-2026-79251Medium· 6.5⚖ disputed
1mo ago

chromium-browser: Google Chrome: Web origin policy bypass via improper input validation (CVE-2026-79251)

A flaw was found in Google Chrome. Improper input validation in the Network component allows a remote attacker to potentially bypass the web origin policy. This can be achieved by enticing a user to visit a specially crafted HTML page. The…

▾ SunlitRed Hat · ChromeEPSS 0.28%via CSAF
CVE-2026-79259Medium· 4.3
1mo ago

Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file

Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.23%via CVEORG
CVE-2026-79066Low· 3.1
1mo ago

Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Improper input validation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-79203Low· 3.1
1mo ago

Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page

Improper input validation in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.26%via CVEORG
CVE-2026-79255Low· 3.1
1mo ago

Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page

Improper input validation in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

▾ SunlitGoogle · ChromeEPSS 0.27%via CVEORG
CVE-2026-65979Medium· 5.5
1mo ago

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.12, the HTJ2K decoder parses a header-length field (PLEN) from a chunk's compr…

▾ SunlitRed HatEPSS 0.18%via NVD
CVE-2026-55371None
1mo ago

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the OpenEXRCore f…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-34959Medium· 4.7
1mo ago

Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value

Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g. X-Forwarded-Pref…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-16434None
1mo ago

Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2)

Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching ^/[^/], blocking //evil.c…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-72711Medium· 6.3PoC
1mo ago

The Lean 4 kernel does not check that the body of an opaque declaration is closed

The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and theorem paths perform, so a value containing a free variable that …

▾ Twilightleanprover · lean4EPSS 0.18%via NVD
CVE-2026-76840Critical· 9.6
1mo ago

RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check

RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrSt…

▾ MidnightEPSS 0.43%via NVD
CVE-2026-76816Low· 3.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH topic names before encoding, al…

▾ SunlitRed Hat · Red Hat JBoss Enterprise Application Platform 7EPSS 0.27%via NVD
CVE-2026-75975High· 7.5
1mo ago

fast-uri: fast-uri: Server-side request forgery via malformed IPv6 normalization (CVE-2026-75975)

A flaw was found in fast-uri, a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not fully validate the IPv6 grammar, allowing invalid trailing text in an authority to be silently discarded. This can lead to a mal…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.38%via CSAF
CVE-2026-55477High· 7.2
1mo ago

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

▾ Twilightmhsanaei · github.com/mhsanaei/3x-ui/v3EPSS 0.61%via GHSA
GHSA-rgqc-3x5p-6gwgMedium
1mo ago

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

▾ Sunlitpostgres-protocol · postgres-protocolvia GHSA
CVE-2026-2996High· 7.5
1mo ago

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. …

▾ TwilightEPSS 0.53%via NVD
CVE-2026-63421High· 7.5
1mo ago

Keystone is a content management system for Node.js

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing a remote unauthentica…

▾ Twilightkeystone-6 · @keystone-6/coreEPSS 0.67%via NVD
CVE-2026-45099Medium
1mo ago

Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale

Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt trusts paths decoded from a downloaded module's .terragrunt-module-manifest during fileM…

▾ Sunlitgruntwork-io · github.com/gruntwork-io/terragruntEPSS 0.54%via NVD
CVE-2026-48755Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary fi…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
CVE-2026-48769Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary com…

▾ Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.73%via NVD
CVE-2026-53541Medium· 4.3
1mo ago

OliveTin gives access to predefined shell commands from a web interface

OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action's configuration. However, prio…

▾ SunlitOliveTin · github.com/OliveTin/OliveTinEPSS 0.38%via NVD
CVE-2026-53587High· 7.5PoC
1mo ago

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in…

▾ Midnightlibgit2 · libgit2EPSS 0.68%via NVD
CVE-2026-77645None
1mo ago

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

▾ SunlitEPSS 0.56%via NVD
CVE-2026-70105Medium· 6.5
1mo ago

Microsoft Word Information Disclosure Vulnerability

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.97%via CVEORG
GHSA-5p3m-vhh6-9236Medium· 6.3
1mo ago

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

▾ Sunlitstigmem-node · stigmem-nodevia GHSA
CVE-2026-49392Medium· 5.3
1mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file p…

▾ Sunlitwazuh · wazuhEPSS 0.30%via NVD
CVE-2026-61711Medium
1mo ago

BuildKit: Custom frontend could bypass Seccomp/AppArmor

BuildKit: Custom frontend could bypass Seccomp/AppArmor

▾ Sunlitmoby · github.com/moby/buildkitEPSS 0.47%via OSV
CVE-2026-52877High· 8.3
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExter…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-52876High· 8.8
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type o…

▾ TwilightEPSS 0.20%via NVD
CVE-2026-54543Medium· 5.4
1mo ago

Froxlor is open source server administration software

Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line delimiters, tab char…

▾ Sunlitfroxlor · froxlor/froxlorEPSS 0.45%via NVD
CWE-20 vulnerabilities (CVEs) — page 9 · VulnSea