VulnSea

CWE-668

CVEs classified under CWE-668, newest first.

46 CVEsRSS

CVE-2026-86551Low· 3.3
2d ago

The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.

The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.

SunlitZTE · NX741JEPSS 0.17%via NVD
CVE-2026-54582Medium· 6.0
5d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non-directory assets that already existed on disk. The affected logic across libmport/check_preconditions.c, libmport/in…

SunlitMidnightBSD · mportEPSS 0.53%via NVD
CVE-2026-92940Critical· 10.0
5d ago

vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https')

vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but metho…

Midnightpatriksimek · vm2EPSS 0.34%via NVD
CVE-2026-50607Low· 2.7
5d ago

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service to unintended ne…

SunlitAcer · System MonitoringEPSS 0.25%via NVD
CVE-2026-54504High· 8.8PoC
5d ago

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with STA…

Midnightandrea9293 · mcp-documentation-serverEPSS 0.67%via NVD
CVE-2026-54495Medium· 4.3
5d ago

The OpenFeature Operator allows users to expose feature flags to applications

The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME…

Sunlitopen-feature · open-feature-operatorEPSS 0.23%via NVD
CVE-2026-61590High· 7.4
6d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface …

Twilightdjust-org · djustEPSS 0.33%via NVD
CVE-2026-85053High· 8.8
2w ago

Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.29%via NVD
CVE-2026-82652Medium· 5.3
3w ago

SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode

SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanism…

SunlitEPSS 0.21%via NVD
CVE-2026-82650Medium· 4.4
3w ago

SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go)

SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint restric…

SunlitEPSS 0.22%via NVD
CVE-2026-79031Low· 3.1
4w ago

Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page

Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

SunlitGoogle · ChromeEPSS 0.33%via CVEORG
CVE-2026-72924None
4w ago

GitHub CLI (gh) is GitHub's official command line tool

GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the local listener created by gh codespace ports forward to all available network interfaces by default. While port forwarding is active, a servi…

SunlitEPSS 0.18%via NVD
CVE-2026-59308Medium· 4.2
1mo ago

In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0

In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0

Sunlitvmware · spring_aiEPSS 0.16%via NVD
CVE-2026-53657High· 8.2
1mo ago

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket

Twilightlima-vm · github.com/lima-vm/lima/v2EPSS 0.20%via GHSA
CVE-2026-73843Critical· 9.6
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication,…

Midnightopenchoreo · github.com/openchoreo/openchoreoEPSS 0.29%via NVD
CVE-2026-72764High· 8.8
1mo ago

n8n's JavaScript task runner shared a single module cache across all users' Code-node executions

n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able to run a Code node could poison a cached module and thereby alter o…

Twilightn8n · n8nEPSS 0.45%via NVD
GHSA-596p-6jv8-775vMedium
1mo ago

Craft CMS: Authenticated leak of secret environment variables

Craft CMS: Authenticated leak of secret environment variables

Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-70606Medium· 5.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol handler returned a ProtocolResponse with a url and no session, E…

Sunlitelectron · electronEPSS 0.16%via NVD
CVE-2026-67427High· 8.6
1mo ago

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Twilightflyto-core · flyto-coreEPSS 0.36%via GHSA
CVE-2026-54727High· 8.2
1mo ago

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

Twilightproot-distro · proot-distroEPSS 0.12%via GHSA
CVE-2026-54497Medium· 6.8
2mo ago

ViewComponent: Reused Component Instances Retain Stale Render Context

ViewComponent: Reused Component Instances Retain Stale Render Context

Sunlitview_component · view_componentEPSS 0.25%via GHSA
CVE-2026-14611Medium· 4.3
2mo ago

A vulnerability has been found in DeepMyst Mysti up to 0.4.0

A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of the file src/managers/MemoryManager.ts of the component Per-Project Auto-Memory Handler. Such manipulation of the arg…

SunlitEPSS 0.43%via NVD
CVE-2026-50202Medium· 5.9
2mo ago

Steeltoe's static JWKS cache shared across schemes and never invalidated

Steeltoe's static JWKS cache shared across schemes and never invalidated

SunlitSteeltoe · Steeltoe.Security.Authentication.JwtBearerEPSS 0.29%via GHSA
GHSA-6c4r-g249-wv3cMedium
2mo ago

OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts

OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts

Sunlitopenclaw · openclawvia GHSA
GHSA-6jcq-6546-qrrwHigh· 8.8
3mo ago

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

Twilightpraisonai · praisonaivia GHSA
CVE-2026-54096High
3mo ago

File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path

File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path

Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.18%via GHSA
CVE-2026-48096Medium· 5.0
3mo ago

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

Sunlitopenfga · github.com/openfga/openfgaEPSS 0.10%via OSV
CVE-2026-45411Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited o…

Midnightvm2_project · vm2EPSS 0.57%via NVD
CVE-2026-44009Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

Midnightvm2_project · vm2EPSS 0.81%via NVD
CVE-2026-44008Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong …

Midnightvm2_project · vm2EPSS 0.85%via NVD
CWE-668 vulnerabilities (CVEs) · VulnSea