VulnSea

CWE-441

CVEs classified under CWE-441, newest first.

72 CVEsRSS

CVE-2026-87502Medium· 4.2
2w ago

Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page

Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security se…

▾ Sunlitgoogle · chromeEPSS 0.22%via NVD
CVE-2026-28614High· 7.8
2w ago

In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy

In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …

▾ Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-28607High· 7.8
2w ago

In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy

In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio…

▾ Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-28603High· 7.8
2w ago

In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy

In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges…

▾ Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-28600High· 7.8
2w ago

In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy

In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i…

▾ Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-28657High· 7.8
2w ago

In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy

In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. Us…

▾ Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-28644High· 7.8
2w ago

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User intera…

▾ Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-28636High· 7.8
2w ago

In setupLayout of PickActivity.java, there is a possible bypass of the "Install unknown apps" security restriction due to a confused deputy

In setupLayout of PickActivity.java, there is a possible bypass of the "Install unknown apps" security restriction due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed.…

▾ Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-28624High· 7.8
2w ago

In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy

In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interact…

▾ Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-28616High· 7.8
2w ago

In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy

In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f…

▾ Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-45520High· 7.8
2w ago

In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy

In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-45519Low· 3.3
2w ago

In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a confused deputy

In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User int…

▾ Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-69531Medium· 5.5
2w ago

Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.

Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.30%via NVD
CVE-2026-86600High· 8.2
2w ago

In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint

In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify …

▾ TwilightSnowflake · snowflake-connector-pythonEPSS 0.51%via NVD
CVE-2026-86115Medium· 5.0
3w ago

Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens

Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL…

▾ Sunlitsimstudioai · simEPSS 0.50%via NVD
CVE-2026-77348High· 8.2
3w ago

Wallos is an open-source, self-hostable personal subscription tracker

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling …

▾ TwilightEPSS 0.43%via NVD
CVE-2026-78682High· 7.5
1mo ago

nltk: NLTK: Server-Side Request Forgery via HTTP Proxy Configuration (CVE-2026-78682)

A flaw was found in NLTK. When an HTTP proxy is configured, a server-side request forgery (SSRF) vulnerability exists in the `nltk.pathsec.urlopen` function. An attacker can exploit this by providing a seemingly valid public URL, which the…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.43%via CSAF
CVE-2026-63643Medium
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through…

▾ Sunlitmagicmirror · magicmirrorEPSS 0.66%via NVD
CVE-2026-73424Medium· 6.5
1mo ago

Astro is a web framework for content-driven websites

Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-73266High· 7.1
1mo ago

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE)

A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a Mana…

▾ TwilightRed Hat · multicluster-engine/clusterclaims-controller-rhel9EPSS 0.35%via NVD
CVE-2026-73079High· 8.5
1mo ago

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider…

▾ TwilightWei-Shaw · sub2apiEPSS 0.39%via NVD
CVE-2026-54663Medium· 6.1
2mo ago

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

▾ Sunlitswagger-typescript-api · swagger-typescript-apiEPSS 0.32%via GHSA
CVE-2026-43910High· 8.2
2mo ago

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor

▾ Twilightappium · io.appium:java-clientEPSS 0.43%via GHSA
CVE-2026-17107High· 8.5
2mo ago

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE)

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests wit…

▾ TwilightRed Hat · multicluster-engine/cluster-proxy-rhel9EPSS 0.57%via NVD
CVE-2026-13062Medium· 6.5
2mo ago

MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the m…

▾ SunlitMongoDB · MongoDB ServerEPSS 0.19%via CVEORG
CVE-2026-16158High· 8.7
2mo ago

Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter

Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore pr…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-53514High· 7.7
2mo ago

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin

▾ Twilightbetter-auth · better-authEPSS 0.20%via GHSA
CVE-2026-53513Critical· 9.6
2mo ago

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints

▾ Midnightbetter-auth · @better-auth/ssoEPSS 0.25%via GHSA
CVE-2026-55430Medium· 5.8
2mo ago

Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.21%via GHSA
CVE-2026-49821High· 7.7
2mo ago

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration

▾ Twilightfission · github.com/fission/fissionEPSS 0.40%via GHSA
CWE-441 vulnerabilities (CVEs) — page 2 · VulnSea