VulnSea

CWE-289

CVEs classified under CWE-289, newest first.

14 CVEsRSS

CVE-2026-92579Medium· 5.4PoC
5d ago

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugi…

TwilightWWBN · AVideoEPSS 0.16%via NVD
CVE-2026-92598Medium· 6.5PoC
5d ago

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient add…

Twilightnodemailer · nodemailerEPSS 0.26%via NVD
CVE-2026-63127High· 8.2PoC
5d ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oau…

Midnightmodelcontextprotocol · rust-sdkEPSS 0.19%via NVD
CVE-2026-12101High· 8.1
6d ago

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.

IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied requests.

TwilightIBM · Verify Identity AccessEPSS 0.27%via NVD
CVE-2026-76169High· 7.5
2w ago

fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler

fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The in…

Twilightfastify · fastifyEPSS 0.51%via NVD
CVE-2026-15980Critical· 9.8
3w ago

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate()…

MidnightEPSS 0.45%via NVD
CVE-2026-32639Medium· 6.8
3w ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend us…

Sunlitwinter · winter/wn-cms-moduleEPSS 0.28%via NVD
CVE-2026-8457Critical· 9.8
1mo ago

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base…

MidnightEPSS 0.44%via NVD
CVE-2026-55075High· 7.4
2mo ago

Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

Twilightcoder · github.com/coder/coder/v2EPSS 0.48%via GHSA
CVE-2026-50627Critical· 9.1
3mo ago

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens

The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Reso…

Midnightapache · cxfEPSS 0.45%via NVD
CVE-2026-44492High· 8.6PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL us…

Midnightaxios · axiosEPSS 0.90%via NVD
CVE-2026-3184Low· 3.7
5mo ago

A flaw was found in util-linux

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by …

Sunlitkernel · util-linuxEPSS 0.44%via NVD
CVE-2026-23903Medium· 5.3
7mo ago

Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files

Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If st…

Sunlitapache · shiroEPSS 0.36%via NVD
CVE-2025-55130Critical· 9.1PoC
8mo ago

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the curren…

Abyssalnodejs · node.jsEPSS 1.7%via NVD
CWE-289 vulnerabilities (CVEs) · VulnSea