VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

622 CVEsRSS

CVE-2026-57227High· 7.5
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages …

▾ TwilightOISF · suricataEPSS 0.70%via NVD
CVE-2026-63452High· 7.5
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small b…

▾ TwilightOISF · suricataEPSS 0.63%via NVD
CVE-2026-63448Medium· 5.9
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain force-completed transactions on flows where Suricata sees payload …

▾ SunlitOISF · suricataEPSS 0.72%via NVD
CVE-2026-57224Medium· 6.5
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions without recording their…

▾ SunlitOISF · suricataEPSS 0.41%via NVD
CVE-2026-69186Medium· 5.3PoC⚖ disputed
1w ago

c-ares is an asynchronous resolver library

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Beca…

▾ Twilightc-ares · c-aresEPSS 0.52%via NVD
CVE-2026-33625High· 8.8PoC
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitra…

▾ MidnightInternLM · lmdeployEPSS 0.44%via NVD
CVE-2026-68914High· 8.7
1w ago

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-14803. Reason: This candidate is a duplicate of CVE-2026-14803. Notes: All CVE users should reference CVE-2026-14803 instead of this candidate.

▾ Twilightmojolicious · mojoEPSS 0.26%via NVD
CVE-2026-93587Low· 3.3
1w ago

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource…

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource…

▾ SunlitImageMagick · ImageMagickEPSS 0.15%via NVD
CVE-2026-93590Low· 3.7
1w ago

ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels

ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted …

▾ SunlitImageMagick · ImageMagickEPSS 0.39%via NVD
CVE-2026-88798Medium· 5.3
1w ago

The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound …

The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound …

▾ SunlitEPSS 0.42%via NVD
CVE-2026-93310Medium· 5.3PoC
1w ago

A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10

A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of the attack is possible. The exploit is …

▾ TwilightO-RAN-SC · SMO OAMEPSS 0.70%via NVD
CVE-2026-93308Medium· 4.3PoC
1w ago

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiate…

▾ TwilightO-RAN-SC · SMO OAMEPSS 0.52%via NVD
CVE-2026-93309Medium· 4.3PoC
1w ago

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched …

▾ TwilightO-RAN-SC · SMO OAMEPSS 0.52%via NVD
CVE-2026-93307Medium· 4.3PoC
1w ago

A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10

A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to uncontrolled memory allocation. The attack…

▾ TwilightO-RAN-SC · SMO OAMEPSS 0.53%via NVD
CVE-2026-68537High· 7.5
1w ago

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…

▾ Twilightfulgur-rs · fulgurEPSS 0.61%via NVD
CVE-2026-68523High· 7.5
1w ago

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…

▾ Twilightfulgur-rs · fulgurEPSS 0.61%via NVD
CVE-2026-86040High· 7.5
1w ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.attachInboundStream in packages/floodsub/src/peer-streams.…

▾ Twilightlibp2p · js-libp2pEPSS 0.67%via NVD
CVE-2026-86000Medium· 5.3PoC
1w ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and V…

▾ Twilightfacelessuser · soupsieveEPSS 0.61%via NVD
CVE-2026-85999Medium· 5.3PoC
1w ago

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used …

▾ Twilightfacelessuser · soupsieveEPSS 0.61%via NVD
CVE-2026-85721High· 7.5PoC
1w ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelM…

▾ Midnightasynchttpclient · org.asynchttpclient:async-http-clientEPSS 0.63%via NVD
CVE-2026-85718Medium· 5.9
1w ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one…

▾ SunlitAsyncHttpClient · async-http-clientEPSS 0.53%via NVD
CVE-2026-92942High· 7.5PoC
1w ago

vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call

vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout only wraps the single call to _runScript() via doWithTimeout() in lib/vm.js, …

▾ Midnightpatriksimek · vm2EPSS 0.49%via NVD
CVE-2026-92879Medium· 4.3
1w ago

A security flaw has been discovered in vgmstream up to r2117

A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is i…

▾ SunlitEPSS 0.59%via NVD
CVE-2026-50285High· 7.5PoC
1w ago

Pomerium is an identity and context-aware access proxy

Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an output-memory limit when DecryptURLValues processes HPKE V…

▾ Midnightpomerium · pomeriumEPSS 0.74%via NVD
CVE-2026-50125High· 7.5PoC
1w ago

MKP is a Model Context Protocol server for Kubernetes

MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the unauthenticated get_resource tool, which accepts attacker-controlled limitByt…

▾ MidnightStacklokLabs · mkpEPSS 0.49%via NVD
CVE-2026-92596High· 7.5PoC
1w ago

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a s…

▾ Midnightnodemailer · nodemailerEPSS 0.82%via NVD
CVE-2026-81872Medium· 6.3PoC
1w ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills its asynchronous export buffer…

▾ Twilightopen-telemetry · opentelemetry-goEPSS 0.52%via NVD
CVE-2026-81869Medium· 5.1PoC
1w ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and string-slice attributes containing…

▾ Twilightopen-telemetry · opentelemetry-goEPSS 0.18%via NVD
CVE-2026-76646High· 7.5
1w ago

A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recomme…

A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recomme…

▾ TwilightApache Software Foundation · Apache MyFacesEPSS 0.58%via NVD
CVE-2026-81875High· 7.5PoC
1w ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker…

▾ Midnighthapifhir · org.hl7.fhir.coreEPSS 0.63%via NVD
CWE-400 vulnerabilities (CVEs) — page 3 · VulnSea