VulnSea

CWE-345

CVEs classified under CWE-345, newest first.

164 CVEsRSS

CVE-2026-47664None
1mo ago

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, the `$import-pnp` operation in Pathling Server accepts a caller-supplied `export…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-19127Medium· 6.5
1mo ago

An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows

An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/life…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-19061Low· 3.7
1mo ago

A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469

A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verificat…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-54764Medium· 5.8
1mo ago

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

▾ Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.28%via GHSA
CVE-2026-54763High
1mo ago

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

▾ Twilighttraefik · github.com/traefik/traefik/v2EPSS 0.24%via GHSA
CVE-2026-67618Medium· 6.5
1mo ago

marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata, which is merged into session configu…

marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata, which is merged into session configu…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-18248Critical· 9.1
1mo ago

@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorize…

@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorize…

▾ MidnightEPSS 0.38%via NVD
CVE-2026-68945High· 8.2
1mo ago

@angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache (CVE-2026-68945)

A flaw was found in Angular's HttpTransferCache component. This component, used for caching HTTP requests during server-side rendering, incorrectly generates cache keys when repeated request parameters are present, causing semantically dif…

▾ TwilightRed Hat · Red Hat Ceph Storage 4EPSS 0.18%via CSAF
CVE-2026-59641None
1mo ago

In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation

In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fip…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-48063Critical
1mo ago

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event…

▾ Midnightbaileys · baileysEPSS 0.22%via NVD
CVE-2026-67307Medium· 6.3
1mo ago

Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity

Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity. This…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-59247High· 7.6
2mo ago

Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged Hex package contents during dependency resolution. During dependency resolution Gleam fetches package metadata …

Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged Hex package contents during dependency resolution. During dependency resolution Gleam fetches package metadata …

▾ Twilightgleam-lang · gleam.run/gleamEPSS 0.18%via NVD
GHSA-pvcr-8mvp-w8qrHigh· 7.7
2mo ago

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-fp43-vj7g-pg92High· 7.5
2mo ago

OmniFaces: Forged combined-resource IDs and related output/push boundaries

OmniFaces: Forged combined-resource IDs and related output/push boundaries

▾ Twilightomnifaces · org.omnifaces:omnifacesvia GHSA
GHSA-qq9h-g4jm-xgf3High· 8.3
2mo ago

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

▾ Twilightbetter-auth · better-authvia GHSA
GHSA-x445-f3h2-j279Medium· 6.8
2mo ago

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them

▾ Sunlitauth · @auth/corevia GHSA
GHSA-8342-988q-86crHigh
2mo ago

n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login

n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login

▾ Twilightn8n · n8nvia GHSA
CVE-2026-49834Medium· 5.9
2mo ago

github.com/sigstore/sigstore-go: sigstore-go: Security Policy Bypass via Compromised Log (CVE-2026-49834)

A flaw was found in sigstore-go, a Go library for Sigstore signing and verification. This vulnerability allows a single compromised transparency log or Certificate Transparency (CT) log to bypass the multi-log threshold requirements. An at…

▾ SunlitRed Hat · Red Hat Trusted Artifact SignerEPSS 0.18%via CSAF
CVE-2026-44434Medium· 5.3
2mo ago

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless reset injection through lack of packet entry validation. The QUIC protocol …

▾ SunlitEPSS 0.21%via NVD
CVE-2026-53536None
2mo ago

Activepieces is an open source AI workflow automation platform

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared signing secret but did not check the token's audience, and combined…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-50526High· 7.0
2mo ago

.NET Tampering Vulnerability

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.22%via CVEORG
CVE-2026-47304High· 8.1
2mo ago

.NET Security Feature Bypass Vulnerability

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
CVE-2026-11901Medium· 5.3
2mo ago

The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1

The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayP…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-53514High· 7.7
2mo ago

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

▾ Twilightbetter-auth · better-authEPSS 0.20%via GHSA
CVE-2026-53516High· 8.3
2mo ago

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email

▾ Twilightbetter-auth · better-authEPSS 0.29%via GHSA
CVE-2026-53513Critical· 9.6
2mo ago

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

▾ Midnightbetter-auth · @better-auth/ssoEPSS 0.25%via GHSA
CVE-2026-53512Critical· 9.1
2mo ago

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins

▾ Midnightbetter-auth · better-authEPSS 0.27%via GHSA
CVE-2026-55430Medium· 5.8
2mo ago

Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.21%via GHSA
CVE-2026-54496Critical· 9.3
2mo ago

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

▾ Midnightzebrad · zebradEPSS 0.32%via GHSA
CVE-2026-49284High· 7.1
2mo ago

SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`

SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`

▾ Twilightsimplesamlphp · simplesamlphp/simplesamlphpEPSS 0.22%via GHSA
CWE-345 vulnerabilities (CVEs) — page 4 · VulnSea