VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

546 CVEsRSS

CVE-2026-76646High· 7.5
5d ago

A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recomme…

A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recomme…

TwilightApache Software Foundation · Apache MyFacesEPSS 0.51%via NVD
CVE-2026-81875High· 7.5PoC
5d ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker…

Midnighthapifhir · org.hl7.fhir.coreEPSS 0.63%via NVD
CVE-2026-81876High· 7.5
5d ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can enter an infinit…

Twilighthapifhir · org.hl7.fhir.coreEPSS 0.63%via NVD
CVE-2026-69147Medium· 6.5PoC
5d ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards …

Twilightvllm-project · vllmEPSS 0.46%via NVD
CVE-2026-68904High· 7.0
5d ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive setting can enter a repeated reconnection cycle when an OPC UA server's clock skew causes …

Twilightnode-opcua-transport · node-opcua-transportEPSS 0.42%via NVD
CVE-2026-63128High· 7.5PoC
5d ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-fo…

Midnightmodelcontextprotocol · rust-sdkEPSS 0.53%via NVD
CVE-2026-79651High· 7.5
5d ago

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitra…

TwilightRed Hat · keycloak-rhel9-containerEPSS 0.62%via NVD
CVE-2026-92362High· 7.3
5d ago

A vulnerability was detected in ag-ui-protocol ag-ui 1.0

A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a manipulation results in resource consumption. The attac…

Twilightag-ui-protocol · ag-uiEPSS 0.51%via NVD
CVE-2026-92363Medium· 4.3
5d ago

A flaw has been found in ag-ui-protocol ag-ui 1.0

A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed…

Sunlitag-ui-protocol · ag-uiEPSS 0.52%via NVD
CVE-2026-92361Medium· 4.3
5d ago

A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0

A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption.…

Sunlitag-ui-protocol · ag-uiEPSS 0.51%via NVD
CVE-2026-73175High· 7.1
5d ago

Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust…

Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust…

TwilightAdvantech · EKI-1242IEIMSEPSS 0.23%via NVD
CVE-2026-92356Medium· 4.3
5d ago

A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1

A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption.…

Sunlita2ui-project · a2uiEPSS 0.39%via NVD
CVE-2026-87828Medium· 5.7
5d ago

The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that causes an uncaught …

The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscribers to write a malformed value that causes an uncaught …

SunlitEPSS 0.24%via NVD
CVE-2026-92220Medium· 5.3⚖ disputed
5d ago

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_tra…

Sunlitvllm-project · vLLMEPSS 0.52%via NVD
CVE-2026-92114Medium· 5.3
6d ago

A vulnerability was identified in a2ui-project a2ui up to 0.10.6

A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functions/safe_regex.ts of the component Basic Catalog. Such manipulation leads to in…

Sunlita2ui-project · a2uiEPSS 0.54%via NVD
CVE-2026-61554High· 7.5PoC
6d ago

emp3r0r is a C2 designed by Linux users for Linux environments

emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenti…

Midnightjm33-m0 · github.com/jm33-m0/emp3r0r/coreEPSS 0.55%via NVD
CVE-2026-87289High· 7.5
6d ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with …

TwilightOracle Corporation · HelidonEPSS 0.46%via NVD
CVE-2026-87285Medium· 6.0
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.14%via NVD
CVE-2026-87283Medium· 6.0
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.11%via NVD
CVE-2026-87282Medium· 6.0
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.14%via NVD
CVE-2026-87279Medium· 6.1
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastru…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.13%via NVD
CVE-2026-87277High· 7.5
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via RD…

TwilightOracle Corporation · Oracle VM VirtualBoxEPSS 0.46%via NVD
CVE-2026-87274Medium· 4.4
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrast…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.11%via NVD
CVE-2026-87267Medium· 5.3
6d ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with network access via R…

SunlitOracle Corporation · Oracle VM VirtualBoxEPSS 0.23%via NVD
CVE-2026-87222High· 7.5
6d ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

TwilightOracle Corporation · Oracle Hyperion Financial ManagementEPSS 0.44%via NVD
CVE-2026-87215High· 7.5
6d ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

Twilightoracle · hyperion_financial_managementEPSS 0.32%via NVD
CVE-2026-87199High· 7.5
6d ago

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with …

Twilightoracle · hyperion_financial_managementEPSS 0.32%via NVD
CVE-2026-87148High· 7.5
6d ago

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthentic…

TwilightOracle Corporation · Oracle Hyperion Data Relationship ManagementEPSS 0.34%via NVD
CVE-2026-87138High· 7.5
6d ago

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security)

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthentic…

TwilightOracle Corporation · Oracle Hyperion Data Relationship ManagementEPSS 0.46%via NVD
CVE-2026-87126High· 7.1
6d ago

Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Reports Security)

Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Reports Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n…

TwilightOracle Corporation · Oracle Report ManagerEPSS 0.40%via NVD
CWE-400 vulnerabilities (CVEs) — page 2 · VulnSea