VulnSea

CWE-345

CVEs classified under CWE-345, newest first.

163 CVEsRSS

CVE-2026-82549High· 8.3
4w ago

A vulnerability was identified in Linux Foundation Magma 1.9.0

A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be la…

▾ TwilightEPSS 0.26%via NVD
CVE-2026-82465Medium· 5.3
4w ago

pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest()

pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destroyed based solely on the NameID, allow…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-82462Medium· 6.5
4w ago

pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation

pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without prop…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-82017High· 7.6PoC
1mo ago

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and u…

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and u…

▾ MidnightIGEL · IGEL OS 12EPSS 0.21%via NVD
GHSA-mf7q-r4rv-jv94High
1mo ago

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature…

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

▾ Twilightcrossplane · github.com/crossplane/crossplane-runtime/v2via OSV
CVE-2026-55663Medium· 5.6
1mo ago

mediasoup is a WebRTC video conferencing system

mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded m…

▾ Sunlitmediasoup · mediasoupEPSS 0.19%via NVD
CVE-2026-75509Medium· 6.5
1mo ago

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing…

▾ SunlitEPSS 0.12%via NVD
CVE-2026-62204Medium· 6.6
1mo ago

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageN…

▾ SunlitEPSS 0.09%via NVD
CVE-2026-58002Medium· 6.5
1mo ago

WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by supp…

WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by supp…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-48105High· 8.3
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) accepts attacker-chosen file paths in manifest-registration proposals w…

▾ TwilightBasekick-Labs · arcEPSS 0.22%via NVD
CVE-2026-48106High· 8.3
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replication/receiver.go` validates only the wire-format envelope (length, opcode)…

▾ TwilightBasekick-Labs · arcEPSS 0.22%via NVD
CVE-2026-44725Medium· 6.6
1mo ago

EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles

EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, the plugin-install REST API and dashboard upload accepted stale grants created with …

▾ SunlitEPSS 0.37%via NVD
CVE-2026-68554Low· 2.3PoC
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an authenticated STUN request on plain UDP or TCP, adjust the STUN header length, …

▾ Twilightcoturn · coturnEPSS 0.19%via NVD
CVE-2026-76245High
1mo ago

stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired

stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliab…

▾ Twilightstigmem-node · stigmem-nodeEPSS 0.24%via NVD
CVE-2026-50575High· 7.7
1mo ago

BetterDesk is a remote desktop management solution

BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Ve…

▾ TwilightEPSS 0.22%via NVD
GHSA-vjf8-9fx6-mv6xMedium
1mo ago

Triton VM Soundness Vulnerability due to Missing Constraint

Triton VM Soundness Vulnerability due to Missing Constraint

▾ Sunlittriton-vm · triton-vmvia GHSA
CVE-2026-52737Medium· 5.3
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra's outbound getblocks or FindBlocks request with a small two-hash inventory and then serve a syntactically valid block w…

▾ Sunlitzebra-consensus · zebra-consensusEPSS 0.26%via NVD
CVE-2026-71858None
1mo ago

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC validation applied to UserDefinedCommands and can invoke Scintilla actions and the internal O…

▾ SunlitEPSS 0.12%via NVD
CVE-2026-73846Medium· 6.5
1mo ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing differen…

▾ Sunlitaborruso · @aborruso/ckan-mcp-serverEPSS 0.19%via NVD
CVE-2026-72817Medium· 6.5
1mo ago

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …

▾ Sunlitgo-chi · github.com/go-chi/chi/middlewareEPSS 0.24%via NVD
CVE-2026-73657Medium· 4.2
1mo ago

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-73840Medium· 5.3
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provi…

▾ Sunlitopenchoreo · github.com/openchoreo/openchoreoEPSS 0.35%via NVD
CVE-2026-14663Medium· 6.5
1mo ago

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the applica…

▾ Sunlitpostgresql · postgresqlEPSS 0.10%via NVD
CVE-2026-73419Medium· 6.8
1mo ago

NextAuth.js provides authentication for Next.js

NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound t…

▾ Sunlitnextauthjs · next-authEPSS 0.25%via NVD
CVE-2026-69105High· 8.1
1mo ago

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

▾ Twilightjfrog · artifactoryEPSS 0.20%via NVD
CVE-2026-62869High· 8.8
1mo ago

Azure Entra ID Spoofing Vulnerability

Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Microsoft EntraEPSS 0.44%via CVEORG
CVE-2026-71576High· 8.5
1mo ago

A flaw was found in multicluster-global-hub

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka clien…

▾ TwilightRed Hat · multicluster-globalhub/multicluster-globalhub-manager-rhel9EPSS 0.23%via NVD
CVE-2026-71965High· 8.8
1mo ago

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access by supplying a malicious remote serve…

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access by supplying a malicious remote serve…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-58262None
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits of the PubKeysBitmap toward the two-thirds validator quorum. These padding bits do not co…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-47664None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, the `$import-pnp` operation in Pathling Server accepts a caller-supplied `export…

▾ SunlitEPSS 0.21%via NVD
CWE-345 vulnerabilities (CVEs) — page 3 · VulnSea