VulnSea

CWE-648

CVEs classified under CWE-648, newest first.

4 CVEsRSS

CVE-2026-76460Critical· 10.0CISA KEV0dayPoC
5d ago

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attack…

Hadalcisco · identity_services_engineEPSS 0.78%via NVD
CVE-2025-24890Medium· 6.8PoC
1w ago

gitoxide is an implementation of git written in Rust

gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered e…

TwilightGitoxideLabs · gitoxideEPSS 0.15%via NVD
CVE-2026-54424High· 8.4PoC
2mo ago

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. …

MidnightEPSS 0.18%via NVD
CVE-2026-41225Critical· 9.1
4mo ago

A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note: Software versions which have reached…

A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note: Software versions which have reached…

MidnightEPSS 0.27%via NVD
CWE-648 vulnerabilities (CVEs) · VulnSea