VulnSea

CWE-345

CVEs classified under CWE-345, newest first.

150 CVEsRSS

CVE-2026-92400Medium· 5.3
today

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account bef…

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account bef…

SunlitEPSS 0.11%via NVD
CVE-2026-92422Medium· 6.5
yesterday

The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing u…

The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing u…

SunlitEPSS 0.11%via NVD
CVE-2026-63405Medium· 5.9PoC
3d ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-compatible REST API in pusher/http.go includes the caller-supplied body_md5 value in the HMAC input but does not calc…

Twilightanycable · github.com/anycable/anycableEPSS 0.17%via NVD
CVE-2026-62874Critical· 10.0
3d ago

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure BillingEPSS 0.32%via NVD
CVE-2026-54608High· 7.1PoC
4d ago

MythicalDash is a Pterodactyl client area

MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments before Stripe checkout succeeds and embed…

MidnightMythicalLTD · MythicalDashEPSS 0.14%via NVD
CVE-2026-54239High· 8.8
4d ago

Faust.js is a headless WordPress toolkit

Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\Auth\encrypt() an…

Twilightwpengine · faustjsEPSS 0.21%via NVD
CVE-2026-54586Medium· 6.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mport_fetch_bundle() paths in libmport/fetch.c accepted non-HTTPS repository and package mirror URLs without a url_is_h…

SunlitMidnightBSD · mportEPSS 0.13%via NVD
CVE-2026-54581High· 8.3
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c could return success when bootstrap index hash verification encountered a missing or invalid hash because the failur…

TwilightMidnightBSD · mportEPSS 0.21%via NVD
CVE-2026-54579Low· 2.3
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validating icmp_id or icmp_seq and parsed the reply using a fixed IP-header offset instead of ip_hl. A network attacker abl…

SunlitMidnightBSD · mportEPSS 0.14%via NVD
CVE-2026-86039High· 8.2
4d ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerR…

Twilightlibp2p · js-libp2pEPSS 0.18%via NVD
CVE-2026-86038High· 7.5PoC
4d ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies …

Midnightlibp2p · @libp2p/gossipsubEPSS 0.16%via NVD
CVE-2026-26950High· 8.1
4d ago

Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability

Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation …

TwilightDell · SmartFabric ManagerEPSS 0.20%via NVD
CVE-2026-78296Medium· 5.3
4d ago

Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.

Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.

SunlitWP ManageNinja LLC · fluent-securityEPSS 0.11%via NVD
CVE-2026-91017Low· 3.7
4d ago

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers t…

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers t…

SunlitEPSS 0.10%via NVD
CVE-2026-61591High· 8.1
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was res…

Twilightdjust-org · djustEPSS 0.17%via NVD
CVE-2026-88592Critical· 9.1PoC
5d ago

kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF)

kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, the URL parameter validated by the filt…

AbyssalEPSS 0.18%via NVD
CVE-2026-63127High· 8.2PoC
5d ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oau…

Midnightmodelcontextprotocol · rust-sdkEPSS 0.19%via NVD
CVE-2026-92138Medium· 4.2
5d ago

The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack …

The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack …

SunlitJenkins Project · Jenkins Bitbucket Server Integration PluginEPSS 0.10%via NVD
CVE-2026-19941Medium· 5.9
5d ago

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This…

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This…

SunlitISC · BIND 9EPSS 0.19%via NVD
CVE-2026-73177High· 8.6
5d ago

Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01

Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images thro…

TwilightAdvantech · EKI-1242IEIMSEPSS 0.14%via NVD
CVE-2026-92360Medium· 6.3
5d ago

A weakness has been identified in ag-ui-protocol ag-ui 1.0

A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_STA…

Sunlitag-ui-protocol · ag-uiEPSS 0.18%via NVD
CVE-2026-73435High· 8.2
5d ago

On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured…

On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured…

TwilightArista Networks · EOSEPSS 0.16%via NVD
CVE-2026-77955Medium· 4.4
5d ago

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents ar…

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents ar…

SunlitNLnet Labs · UnboundEPSS 0.13%via NVD
CVE-2026-84906Medium· 5.3PoC
5d ago

The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or w…

The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or w…

TwilightEPSS 0.14%via NVD
CVE-2026-85641Medium· 4.3
5d ago

The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored entry values, al…

The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored entry values, al…

SunlitEPSS 0.13%via NVD
CVE-2026-73450Medium· 6.9
5d ago

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-pri…

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-pri…

SunlitArista Networks · EOSEPSS 0.13%via NVD
CVE-2026-73437Critical· 9.6
6d ago

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured a…

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured a…

MidnightArista Networks · EOSEPSS 0.20%via NVD
CVE-2026-54167High· 8.2
6d ago

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processi…

Twilighttektoncd · pipelines-as-codeEPSS 0.18%via NVD
CVE-2026-88819Medium· 6.3
1w ago

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

SunlitEclipse Foundation · Eclipse Data Plane CoreEPSS 0.12%via NVD
CVE-2026-57122High· 8.6
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned …

TwilightMervinPraison · PraisonAIEPSS 0.13%via NVD
CWE-345 vulnerabilities (CVEs) · VulnSea