VulnSea

CWE-471

CVEs classified under CWE-471, newest first.

6 CVEsRSS

CVE-2026-92949Medium· 4.0PoC
5d ago

vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections

vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescr…

Twilightpatriksimek · vm2EPSS 0.25%via NVD
CVE-2026-59299Low· 3.1
3w ago

Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier

Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier

SunlitEPSS 0.15%via NVD
CVE-2026-50481Critical· 9.9
1mo ago

Azure Active Directory Elevation of Privilege Vulnerability

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

MidnightMicrosoft · Azure Active DirectoryEPSS 0.56%via CVEORG
GHSA-cmwh-pvxp-8882Medium
3mo ago

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

Sunlitdompurify · dompurifyvia GHSA
CVE-2026-54267High
3mo ago

Angular Client Hydration DOM Clobbering & Response-Cache Poisoning

Angular Client Hydration DOM Clobbering & Response-Cache Poisoning

Twilightangular · @angular/coreEPSS 0.32%via GHSA
CVE-2024-34517Medium· 6.5
2y ago

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

Sunlitneo4j · neo4jEPSS 0.63%via NVD
CWE-471 vulnerabilities (CVEs) · VulnSea