VulnSea

CWE-345

CVEs classified under CWE-345, newest first.

164 CVEsRSS

CVE-2026-3012High· 8.0
4mo ago

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store…

▾ Twilightredhat · openshift_container_platformEPSS 0.23%via NVD
CVE-2026-25602Low· 2.3
4mo ago

Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server)

Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the…

▾ SunlitMesalvo · Meona ServerEPSS 0.09%via NVD
CVE-2026-4984High· 8.2
6mo ago

The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it fetches user-controlled URLs ('MediaUrlN' parameters) using HTTP requests that include …

The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it fetches user-controlled URLs ('MediaUrlN' parameters) using HTTP requests that include …

▾ Twilightbotpress · botpressEPSS 0.18%via NVD
CVE-2026-33243High· 8.2
6mo ago

barebox is a bootloader

barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booti…

▾ Twilightpengutronix · bareboxEPSS 0.12%via NVD
CVE-2026-32597High· 7.5PoC
6mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not …

▾ Midnightpyjwt_project · pyjwtEPSS 0.28%via NVD
CVE-2026-30792High· 8.1
6mo ago

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message Manipulation via Man-in-t…

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message Manipulation via Man-in-t…

▾ TwilightEPSS 0.29%via NVD
CVE-2026-26007Medium· 6.5
7mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), l…

▾ Sunlitcryptography.io · cryptographyEPSS 0.34%via NVD
CVE-2026-22703Medium· 5.5
8mo ago

github.com/sigstore/cosign: Cosign verification accepts any valid Rekor entry under certain conditions (CVE-2026-22703)

A data verification flaw has been discovered in the golang cosign library. A Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact's digest, signature or public key…

▾ SunlitRed Hat · OpenShift PipelinesEPSS 0.11%via CSAF
CVE-2025-59700Low· 3.9
9mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of …

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physically proximate attacker with root access to modify the Recovery Partition (because of a lack of …

▾ Sunlitentrust · nshield_5c_firmwareEPSS 0.18%via NVD
CVE-2025-34337None
10mo ago

eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryption to protect URL parameters, but exposes an encryption ora…

eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryption to protect URL parameters, but exposes an encryption ora…

▾ SunlitEPSS 0.27%via NVD
CVE-2025-71370High· 8.1
1y ago

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

▾ Twilightpicklescan · picklescanEPSS 0.54%via OSV
CVE-2024-12369Medium· 4.2
1y ago

A vulnerability was found in OIDC-Client

A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stol…

▾ SunlitEPSS 0.24%via NVD
CVE-2023-38831High· 7.8CISA KEV0dayPoC
3y ago

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and al…

▾ Abyssalrarlab · winrarEPSS 100%via NVD
CVE-2021-45419High· 8.8
4y ago

Certain Starcharge products are affected by Improper Input Validation

Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <= 1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0 and Titan 180 Premium <= 1.3.0.0.6 - Fixed: 1.3.0.0.9.

▾ Twilightstarcharge · titan_180_premium_firmwareEPSS 0.46%via NVD
CWE-345 vulnerabilities (CVEs) — page 6 · VulnSea