VulnSea

CWE-353

CVEs classified under CWE-353, newest first.

9 CVEsRSS

CVE-2026-49450High· 7.1
yesterday

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.…

Twilightlaurent22 · joplinvia NVD
CVE-2026-76853High· 8.1
1w ago

Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation

Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in put_parame_file_cgi.c to bypass restr…

TwilightNetcore · NR268EPSS 0.22%via NVD
CVE-2026-84533Medium· 5.3
1w ago

A cryptographic issue was addressed with improved integrity checks

A cryptographic issue was addressed with improved integrity checks. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An attacker in a privileged network position may be able to modify network traffic.

Sunlitapple · ipadosEPSS 0.13%via NVD
CVE-2026-89179Medium· 4.3
1w ago

WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability

WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, there…

SunlitHowyar · WeenyGeniusEPSS 0.11%via NVD
CVE-2026-81049Medium· 4.4
1w ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

Sunlitdell · thinosEPSS 0.10%via NVD
CVE-2026-58224Medium· 6.5
1mo ago

A flaw was found in Samba's CTDB, the clustered database service used by Samba

A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets containing invalid field lengths, improperly terminated strings,…

Sunlitsamba · sambaEPSS 0.29%via NVD
CVE-2026-18536None
1mo ago

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::En…

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::En…

SunlitEPSS 0.15%via NVD
CVE-2026-48995Medium
2mo ago

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

Sunlitpnpm · pnpmEPSS 0.17%via GHSA
GHSA-6vvh-pxr4-25r7Medium
3mo ago

PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption

PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption

Sunlitweb-token · web-token/jwt-experimentalvia GHSA
CWE-353 vulnerabilities (CVEs) · VulnSea