VulnSea

CWE-349

CVEs classified under CWE-349, newest first.

4 CVEsRSS

CVE-2026-19033Medium· 6.5
5d ago

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess…

SunlitISC · BIND 9EPSS 0.20%via NVD
CVE-2026-78301Medium· 5.8
5d ago

A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut

A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the confi…

SunlitISC · BIND 9EPSS 0.18%via NVD
CVE-2026-54047Critical· 9.2
1w ago

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies …

MidnightLaciSynchroni · serverEPSS 0.23%via NVD
CVE-2026-54625Medium· 4.8
1mo ago

django CMS is a content management system powered by Django

django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key funct…

Sunlitdjango-cms · django-cmsEPSS 0.15%via NVD
CWE-349 vulnerabilities (CVEs) · VulnSea