VulnSea

CWE-424

CVEs classified under CWE-424, newest first.

6 CVEsRSS

CVE-2026-37008High· 8.1PoC
1w ago

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's co…

MidnightCrewAI · CrewAIEPSS 0.13%via NVD
CVE-2026-82754Medium· 6.3
2w ago

Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_ser…

Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix. oauth2_ser…

Sunlitash-project · ash_authentication_oauth2_serverEPSS 0.39%via NVD
CVE-2026-82586High· 8.2
2w ago

Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manife…

Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list. AshLua exposes Ash resources to Lua scripts, gated by a manife…

Twilightash-project · ash_luaEPSS 0.33%via NVD
CVE-2026-86145High· 8.2
2w ago

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a …

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a …

TwilightPCRE · PCRE2EPSS 0.37%via NVD
CVE-2026-58428Medium· 6.5
2mo ago

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

Sunlitgitea · code.gitea.io/giteaEPSS 0.33%via GHSA
CVE-2026-0268Medium· 4.4
3mo ago

A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.

A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.

Sunlitpaloaltonetworks · prisma_access_agentEPSS 0.10%via NVD
CWE-424 vulnerabilities (CVEs) · VulnSea