VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

623 CVEsRSS

CVE-2026-69222High· 7.5
1mo ago

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, the join filter in src/filters/array.ts computes complexity from array.length and separator length instead of the total string length p…

▾ Twilightliquidjs · liquidjsEPSS 0.63%via NVD
GHSA-p77j-g7h5-r2vwHigh
1mo ago

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

▾ Twilightgeolens · geolensvia GHSA
CVE-2026-49289High· 7.5
1mo ago

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML messages. XPath ev…

▾ Twilightsimplesamlphp · simplesamlphp/saml2EPSS 0.78%via NVD
CVE-2026-70927High· 7.5
1mo ago

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer)

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-70908High· 7.5
1mo ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-70906High· 7.5
1mo ago

Vulnerability in Oracle Java SE (component: 2D)

Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…

▾ TwilightRed Hat · Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)EPSS 0.46%via NVD
CVE-2026-68924Medium· 4.9
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs that an archive member exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE is being skipped but do…

▾ Sunlitmobsf · mobsfEPSS 0.59%via NVD
CVE-2026-65347Medium· 6.5
1mo ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service.

▾ Sunlitapple · ipadosEPSS 0.42%via NVD
CVE-2026-65976Medium· 6.5
1mo ago

Deskflow is a keyboard and mouse sharing app

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messages to ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChunk.cpp, causing the ser…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-68005High· 7.5
1mo ago

An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_request() function

An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_request() function

▾ TwilightEPSS 0.58%via NVD
CVE-2026-71486Medium· 4.3
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, choice…

▾ Sunlitvllm · vllmEPSS 0.47%via NVD
CVE-2026-71491High· 7.5
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption t…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.26%via NVD
CVE-2026-59902High· 7.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedByt…

▾ Twilightnetty · nettyEPSS 0.67%via NVD
CVE-2026-64868High· 7.5
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodie…

▾ TwilightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.64%via NVD
CVE-2026-73057High· 7.5
1mo ago

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values an…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-74797Low· 3.1
1mo ago

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages

OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling …

▾ Sunlitopentofu · github.com/opentofu/opentofuEPSS 0.28%via NVD
CVE-2026-18549High· 7.5
1mo ago

@fastify/multipart is a multipart form-data parser for Fastify

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the …

▾ TwilightEPSS 0.60%via NVD
CVE-2026-73566High· 7.5
1mo ago

node-tar is a tar archive manipulation library for Node.js

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(..…

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.53%via NVD
CVE-2026-73561High· 7.5
1mo ago

Hub is a Node.js WebSocket server and client with added features

Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadDefaultConnectionEventListeners to call requestClientId, which calls rpc.send for the get…

▾ TwilightEPSS 0.61%via NVD
CVE-2026-73507High· 7.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unau…

▾ Twilightnetty · nettyEPSS 0.79%via NVD
CVE-2026-73556Medium· 5.3⚖ disputed
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compi…

▾ Sunlitvllm · vllmEPSS 0.52%via NVD
CVE-2026-33818High· 7.5
1mo ago

Enforce maximum recursion depth in encoding/asn1

Enforce maximum recursion depth in encoding/asn1

▾ Twilightstdlib · stdlibEPSS 0.57%via OSV
CVE-2026-73568High· 7.5
1mo ago

py-libp2p is the Python implementation of the libp2p networking stack

py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly…

▾ Twilightlibp2p · libp2pEPSS 0.49%via NVD
CVE-2026-73559Medium· 6.5
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in vllm/entrypoints/openai/completion/protocol.py accepts an unbounded list[str] or list[list…

▾ Sunlitvllm · vllmEPSS 0.55%via NVD
CVE-2026-73413None
1mo ago

Shescape is a simple shell escape library for JavaScript

Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/compose.js repeatedly joins and slices flag fragments when flagProtection is enabled, which…

▾ SunlitEPSS 0.59%via NVD
CVE-2026-73216Medium· 6.5
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c prematurely calls dec_quota() and releases bandwidth accounting during the first-stage clos…

▾ SunlitEPSS 0.57%via NVD
CVE-2026-73215None
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks the unused odd sibling port as TPS_TAKEN_ODD for an EVEN-PORT Allocate request with rese…

▾ SunlitEPSS 0.45%via NVD
CVE-2026-73214None
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment() state fo…

▾ SunlitEPSS 0.58%via NVD
CVE-2026-65785Medium· 6.5
1mo ago

Windows DHCP Client Denial of Service Vulnerability

Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.

▾ SunlitMicrosoft · Windows 11 Version 24H2EPSS 0.58%via CVEORG
CVE-2026-73228Medium· 5.3
1mo ago

Django REST framework is a toolkit for building Web APIs

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser f…

▾ Sunlitdjangorestframework · djangorestframeworkEPSS 0.56%via NVD
CWE-400 vulnerabilities (CVEs) — page 11 · VulnSea