VulnSea

CWE-664

CVEs classified under CWE-664, newest first.

13 CVEsRSS

CVE-2026-20336High· 8.8
6d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software en…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software en…

TwilightCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.20%via NVD
CVE-2026-54251High· 8.7
1w ago

netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty

netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequest…

Twilightnetty · netty-incubator-codec-ohttpEPSS 0.29%via NVD
CVE-2026-84635Medium· 6.5⚖ disputed
1w ago

A logic issue was addressed with improved state management

A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpec…

Sunlitapple · safariEPSS 0.35%via NVD
CVE-2026-20353Critical· 9.8
1w ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review r…

MidnightCisco · Cisco Secure EmailEPSS 0.40%via NVD
CVE-2026-86203Low· 3.7
1w ago

PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients

PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causin…

Sunlitpmmp · PocketMine-MPEPSS 0.27%via NVD
CVE-2026-79603Medium· 4.3
2w ago

x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them

x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen (if needed) when the page is re-used. Since it's possible for the page to be scrubbed ahead of the TLB flush,…

SunlitXen · XenEPSS 0.23%via NVD
CVE-2026-20274Critical· 9.8
2w ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases tha…

Midnightcisco · ios_xrEPSS 0.73%via NVD
CVE-2026-18549High· 7.5
1mo ago

@fastify/multipart is a multipart form-data parser for Fastify

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the …

TwilightEPSS 0.34%via NVD
CVE-2026-19380Low· 2.3
1mo ago

A vulnerability was identified in Mullvad wireguard.sys 0.10.1

A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to …

SunlitEPSS 0.12%via NVD
CVE-2026-20269High· 8.6
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

Twilightcisco · ios_xeEPSS 0.28%via NVD
CVE-2026-20158High· 7.5
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

Twilightcisco · roomosEPSS 0.47%via NVD
CVE-2026-43503High· 8.8PoC
4mo ago

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SH…

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail to propagate the SKBFL_SH…

Midnightlinux · linux_kernelEPSS 0.34%via NVD
CVE-2019-16779Medium· 5.8
6y ago

In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket

In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, retur…

Sunlitexcon_project · exconEPSS 1.4%via NVD
CWE-664 vulnerabilities (CVEs) · VulnSea