VulnSea

CWE-405

CVEs classified under CWE-405, newest first.

14 CVEsRSS

CVE-2026-75029Medium· 5.3
6d ago

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record)

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can c…

SunlitISC · BIND 9EPSS 0.40%via NVD
CVE-2026-68531Low· 2.1
1w ago

Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit …

Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit …

SunlitConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-87011High· 7.5PoC
1w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery doc…

Midnightopenwebui · open_webuiEPSS 0.36%via NVD
CVE-2026-86432Medium· 5.3
2w ago

commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag

commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers can provide deeply nested Markdown or AST structures to cause qua…

Sunlitthephpleague · commonmarkEPSS 0.25%via NVD
CVE-2026-82309Medium· 4.3
2w ago

Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns issues one PTR query for the client add…

Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns issues one PTR query for the client add…

SunlitEPSS 0.24%via NVD
CVE-2026-84310Medium
3w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines wi…

Sunlitpypdf · pypdfEPSS 0.14%via NVD
CVE-2026-54874High· 7.5
4w ago

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to mak…

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to mak…

Twilightopenssl · opensslEPSS 0.52%via NVD
CVE-2026-23930High· 7.5
1mo ago

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend popup.testtriggerexpr action, leading to potential denial of service.

Twilightzabbix · zabbixEPSS 0.36%via NVD
CVE-2026-72914High· 7.5
1mo ago

Mastodon is a free, open-source social network server based on ActivityPub

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController and Api::V1::Admin::Reten…

TwilightEPSS 0.45%via NVD
GHSA-mj63-m3rc-8pprMedium· 5.3
1mo ago

league/commonmark: Denial of service via deeply nested XML output

league/commonmark: Denial of service via deeply nested XML output

Sunlitleague · league/commonmarkvia GHSA
CVE-2026-45822High· 7.5
2mo ago

decode-uri-component: decode-uri-component: Denial of Service via crafted input (CVE-2026-45822)

A flaw was found in the `decode-uri-component` library. This vulnerability allows a remote attacker to trigger a Denial of Service (DoS) by submitting specially crafted input. The `decode()` function, when processing a large number of enco…

TwilightRed Hat · Red Hat Quay 3.12EPSS 0.51%via CSAF
CVE-2026-47774High· 7.5
3mo ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remot…

Twilightenvoyproxy · envoyEPSS 0.97%via NVD
CVE-2026-22775High· 7.5
8mo ago

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potenti…

Twilightsvelte · devalueEPSS 0.64%via NVD
CVE-2026-22774High· 7.5
8mo ago

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.parse to consume excessive CPU time and/or memory, potenti…

Twilightsvelte · devalueEPSS 0.64%via NVD
CWE-405 vulnerabilities (CVEs) · VulnSea