VulnSea

CWE-400

CVEs classified under CWE-400, newest first.

623 CVEsRSS

CVE-2026-69202High· 7.5
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/2 flow-control window is replenished according to bytes received from the network rather than bytes consumed by the application, while each strea…

▾ Twilighthttp4s · org.http4s:http4s-ember-core_2.12EPSS 0.63%via NVD
CVE-2026-76821High· 7.1
1w ago

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260706.0, the JSON ingestion mapper's extractWithRegexp formula function compiled a user-supplied regular expression with the…

▾ TwilightOpenCTI-Platform · openctiEPSS 0.47%via NVD
CVE-2026-69213High· 7.5
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can c…

▾ Twilighthttp4s · http4sEPSS 0.63%via NVD
CVE-2026-69209High· 7.5
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts dec…

▾ Twilighthttp4s · http4sEPSS 0.63%via NVD
CVE-2026-69208High· 7.5
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes fresh nonces and stops eviction at the first stale nonce because its stale-nonce comparison is inverted. On an applic…

▾ Twilighthttp4s · http4sEPSS 0.77%via NVD
CVE-2026-58483High· 7.5PoC
1w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read in src/index.ts passes a caller-supplied URL to readUrlContent() in src/url-rea…

▾ Midnightihor-sokoliuk · mcp-searxngEPSS 0.67%via NVD
CVE-2026-11926High· 7.5
1w ago

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

▾ TwilightIBM · Verify Identity AccessEPSS 0.31%via NVD
CVE-2026-21588High· 7.1
1w ago

This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, wit…

This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, wit…

▾ TwilightAtlassian · Confluence Data CenterEPSS 0.29%via NVD
CVE-2026-91941High· 7.5
1w ago

Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service

Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to …

▾ Twilightunclecode · crawl4aiEPSS 0.49%via NVD
CVE-2026-91969Medium· 6.5
1w ago

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions…

▾ Sunlitgo-vikunja · vikunjaEPSS 0.44%via NVD
CVE-2026-91971Medium· 6.5PoC
1w ago

Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts

Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts. Attackers can upload small images wit…

▾ Twilightgo-vikunja · vikunjaEPSS 0.44%via NVD
CVE-2026-91979Medium· 6.5
1w ago

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausti…

▾ Sunlitgo-vikunja · vikunjaEPSS 0.44%via NVD
CVE-2026-92003Medium· 6.9
1w ago

Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:  - API requests with no authentication key;  - requests…

Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:  - API requests with no authentication key;  - requests…

▾ SunlitMISP · MISPEPSS 0.57%via NVD
CVE-2026-90878Medium· 4.3PoC
1w ago

A vulnerability was determined in vllm-project vLLM up to 0.27.1

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource co…

▾ Twilightvllm-project · vLLMEPSS 0.53%via NVD
CVE-2026-53941Medium· 6.9
1w ago

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe library resolver can allow an unprivileged container to co…

▾ Sunlitinspektor-gadget · inspektor-gadgetEPSS 0.52%via NVD
CVE-2026-53954Medium· 4.3
1w ago

Bugsink is a self-hosted error tracking tool

Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied with an incoming event, allowing a caller with a valid project DSN to submit an unusually large tag set and force exce…

▾ Sunlitbugsink · bugsinkEPSS 0.56%via NVD
CVE-2026-48987Medium· 6.5PoC
1w ago

pyLoad is a free and open-source download manager written in Python

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid submitted to the aut…

▾ Twilightpyload · pyloadEPSS 0.44%via NVD
CVE-2026-12759Medium· 6.5
1w ago

IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.

IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.

▾ SunlitIBM · Cloud Pak for Business AutomationEPSS 0.22%via NVD
CVE-2026-65410High· 7.5
1w ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system …

▾ Twilightapple · ipadosEPSS 0.50%via NVD
CVE-2026-84553High· 7.5
1w ago

A resource exhaustion issue was addressed with improved input validation

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause a denial-of-service.

▾ Twilightapple · macosEPSS 0.70%via NVD
CVE-2026-17463Medium· 6.5
1w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption.

▾ SunlitIBM · Db2EPSS 0.34%via NVD
CVE-2026-88932Medium· 5.3
1w ago

multer is a Node.js middleware for handling multipart/form-data uploads

multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup a…

▾ SunlitRed Hat · Red Hat Developer HubEPSS 0.53%via NVD
CVE-2026-90927Medium· 6.5PoC
1w ago

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages…

▾ Twilightfilebrowser · filebrowserEPSS 0.44%via NVD
CVE-2026-90928Medium· 6.5PoC
1w ago

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request co…

▾ Twilightfilebrowser · filebrowserEPSS 0.44%via NVD
CVE-2026-53495Medium· 6.8
1w ago

containerd is an open-source container runtime

containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go …

▾ Sunlitcontainerd · containerdEPSS 0.16%via NVD
CVE-2026-50270High· 7.5
1w ago

dd-trace-java is a Datadog APM client for Java

dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply…

▾ TwilightDataDog · dd-trace-javaEPSS 0.79%via NVD
CVE-2026-50276High· 7.5
1w ago

dd-trace-rb is Datadog's client library for Ruby

dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits app…

▾ TwilightDataDog · dd-trace-rbEPSS 0.79%via NVD
CVE-2026-90582Medium· 5.3PoC
2w ago

A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0

A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consum…

▾ Twilightevanchiu · serverless-todoEPSS 0.70%via NVD
CVE-2026-90584Medium· 5.3PoC
2w ago

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation c…

▾ TwilightTooTallNate · Java-WebSocketEPSS 0.72%via NVD
CVE-2026-90554Medium· 6.2
2w ago

vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models

vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _extract_audio_from_videos calls load_audio_pyav(BytesIO(vi…

▾ Sunlitvllm · vllmEPSS 0.20%via NVD
CWE-400 vulnerabilities (CVEs) — page 6 · VulnSea