VulnSea

CWE-354

CVEs classified under CWE-354, newest first.

15 CVEsRSS

CVE-2026-92701Critical· 9.1PoC
3d ago

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expe…

Abyssalultravioletrs · cocosEPSS 0.22%via NVD
CVE-2026-54580High· 8.3
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures t…

TwilightMidnightBSD · mportEPSS 0.25%via NVD
CVE-2026-54578Low· 2.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than …

SunlitMidnightBSD · mportEPSS 0.11%via NVD
CVE-2026-73459High· 7.4
5d ago

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This …

TwilightArista Networks · EOSEPSS 0.16%via NVD
CVE-2026-76852High· 8.8
6d ago

Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks

Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature valid…

TwilightNetcore · NR268EPSS 0.23%via NVD
CVE-2026-54174High· 8.3
1w ago

melange allows users to build apk packages using declarative pipelines

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but…

Twilightchainguard-dev · melangeEPSS 0.10%via NVD
CVE-2026-72929High· 7.8
1w ago

Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.

Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 11 version 23H2EPSS 0.22%via NVD
CVE-2026-82549High· 8.3
3w ago

A vulnerability was identified in Linux Foundation Magma 1.9.0

A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be la…

TwilightEPSS 0.19%via NVD
CVE-2025-61480High· 7.5
3w ago

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.

TwilightEPSS 0.13%via NVD
CVE-2026-75803Critical· 9.1⚖ disputed
3w ago

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: …

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function. Impact summary: …

Midnightopenssl · opensslEPSS 0.22%via NVD
CVE-2026-59642High· 7.5
1mo ago

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips …

TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.15%via NVD
CVE-2026-50021Medium· 6.8
2mo ago

pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field

pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field

Sunlitpnpm · pnpmEPSS 0.18%via GHSA
CVE-2026-28498High· 7.5PoC
6mo ago

Authlib is a Python library which builds OAuth and OpenID Connect servers

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. S…

Midnightauthlib · authlibEPSS 0.23%via NVD
CVE-2026-26007Medium· 6.5
7mo ago

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), l…

Sunlitcryptography.io · cryptographyEPSS 0.35%via NVD
CVE-2024-3727High· 8.3
2y ago

A flaw was found in the github.com/containers/image library

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

Twilightcontainers · github.com/containers/imageEPSS 1.3%via NVD
CWE-354 vulnerabilities (CVEs) · VulnSea