VulnSea

CWE-345

CVEs classified under CWE-345, newest first.

164 CVEsRSS

CVE-2026-92360Medium· 6.3
1w ago

A weakness has been identified in ag-ui-protocol ag-ui 1.0

A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_STA…

▾ Sunlitag-ui-protocol · ag-uiEPSS 0.21%via NVD
CVE-2026-73435High· 8.2
1w ago

On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured…

On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured…

▾ TwilightArista Networks · EOSEPSS 0.19%via NVD
CVE-2026-77955Medium· 4.4
1w ago

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents ar…

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents ar…

▾ Sunlitnlnetlabs · unboundEPSS 0.17%via NVD
CVE-2026-84906Medium· 5.3PoC
1w ago

The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or w…

The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or w…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-85641Medium· 4.3
1w ago

The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored entry values, al…

The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored entry values, al…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-73450Medium· 6.9
1w ago

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-pri…

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-pri…

▾ SunlitArista Networks · EOSEPSS 0.16%via NVD
CVE-2026-73437Critical· 9.6
1w ago

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured a…

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured a…

▾ MidnightArista Networks · EOSEPSS 0.21%via NVD
CVE-2026-54167High· 8.2
1w ago

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processi…

▾ Twilighttektoncd · pipelines-as-codeEPSS 0.27%via NVD
CVE-2026-88819Medium· 6.3
1w ago

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

▾ SunlitEclipse Foundation · Eclipse Data Plane CoreEPSS 0.17%via NVD
CVE-2026-57122High· 8.6
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signatures only when WHATSAPP_APP_SECRET or LINEAR_WEBHOOK_SECRET is configured and otherwise parse and dispatch unsigned …

▾ TwilightMervinPraison · PraisonAIEPSS 0.19%via NVD
CVE-2026-89050Medium· 4.3
2w ago

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a p…

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a p…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-45057Medium· 4.9
2w ago

matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk

matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself i…

▾ Sunlitmatrix-org · matrix-sdk-uiEPSS 0.23%via NVD
CVE-2026-89251Medium· 6.5PoC
2w ago

AVideo Missing Authorization via AD_Server log.php Wallet Credit

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign vid…

▾ TwilightWWBN · AVideoEPSS 0.18%via CVEORG
CVE-2026-86809Medium· 5.3
2w ago

The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to comple…

The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to comple…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-82215Medium· 5.9
2w ago

The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's mercha…

The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's mercha…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-54174High· 8.3
2w ago

melange allows users to build apk packages using declarative pipelines

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but…

▾ Twilightchainguard-dev · melangeEPSS 0.15%via NVD
CVE-2026-80172Critical· 9.8
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could…

▾ MidnightDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.25%via CVEORG
CVE-2026-83537Medium· 5.3
2w ago

The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.

The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.

▾ SunlitEPSS 0.16%via NVD
CVE-2026-73316High· 7.5PoC
2w ago

XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check

XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times by exploiting a missing duplicate transaction ID check. Attackers …

▾ Midnightxenforo · xenforoEPSS 0.27%via NVD
CVE-2026-84043Medium· 5.3
3w ago

The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signat…

The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signat…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-85621Medium· 6.5PoC
3w ago

LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters

LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters. The webhook route (/api/agent/webhooks/:platform) is unauthenticated by design and delegates verification to each a…

▾ Twilightlobehub · lobehubEPSS 0.20%via NVD
CVE-2026-85008Low· 3.7
3w ago

undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is n…

undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is n…

▾ Sunlitnodejs · undiciEPSS 0.15%via NVD
CVE-2026-85435Critical· 9.1
3w ago

MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes

MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to…

▾ MidnightEPSS 0.26%via NVD
CVE-2026-85431High· 7.5
3w ago

MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen

MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to the configured port to inject arbitrary va…

▾ TwilightEPSS 2.8%via NVD
CVE-2026-85430Critical· 9.1
3w ago

MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact

MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagr…

▾ MidnightEPSS 1.3%via NVD
CVE-2026-85434Critical· 9.1
3w ago

MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes

MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker…

▾ MidnightEPSS 0.26%via NVD
CVE-2026-85429High· 7.5
3w ago

MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source

MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate othe…

▾ TwilightEPSS 0.24%via NVD
CVE-2026-53728High· 7.1PoC
3w ago

Medplum is a developer platform that enables development of healthcare apps

Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts attacker-controlled redirect URIs that only need to start with a r…

▾ Midnightmedplum · medplumEPSS 0.20%via NVD
CVE-2026-19219High· 8.1
3w ago

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material …

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material …

▾ TwilightEPSS 0.16%via NVD
CVE-2026-20355Medium· 5.9
3w ago

Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. …

▾ SunlitCisco · Cisco Secure EmailEPSS 0.16%via CVEORG
CWE-345 vulnerabilities (CVEs) — page 2 · VulnSea