VulnSea

CWE-668

CVEs classified under CWE-668, newest first.

49 CVEsRSS

CVE-2026-45411Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited o…

▾ Midnightvm2_project · vm2EPSS 0.90%via NVD
CVE-2026-44009Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

▾ Midnightvm2_project · vm2EPSS 0.71%via NVD
CVE-2026-44008Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong …

▾ Midnightvm2_project · vm2EPSS 0.90%via NVD
CVE-2026-20160Critical· 9.8
5mo ago

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability…

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability…

▾ Midnightcisco · smart_software_manager_on-premEPSS 0.91%via NVD
CVE-2026-2297None
6mo ago

The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files

The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event ther…

▾ SunlitEPSS 0.21%via NVD
CVE-2024-13484High· 8.2
1y ago

A flaw was found in openshift-gitops-operator-container

A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can ha…

▾ TwilightEPSS 0.22%via NVD
CVE-2021-46921High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_slowpath() While this code is executed with the wait_lock held, a reader can acquire the lock without holding wait_l…

In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_slowpath() While this code is executed with the wait_lock held, a reader can acquire the lock without holding wait_l…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-21626High· 8.6PoC
2y ago

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc…

▾ Midnightlinuxfoundation · runcEPSS 18%via NVD
CVE-2024-0443Medium· 5.5
2y ago

A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem

A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), w…

▾ Sunlitlinux · linux_kernelEPSS 0.25%via NVD
CVE-2023-29538Medium· 4.3
3y ago

Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request

Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability af…

▾ Sunlitmozilla · firefoxEPSS 0.40%via NVD
CVE-2022-38474Medium· 4.3
3y ago

A website that had permission to access the microphone could record audio without the audio notification being shown

A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once perm…

▾ Sunlitmozilla · firefox_mobileEPSS 0.39%via NVD
CVE-2022-24139High· 7.8
4y ago

In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes

In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes. ASCService first tries to connect before trying to create the named…

▾ Twilightiobit · advanced_system_careEPSS 0.37%via NVD
CVE-2021-45420Critical· 9.8PoC
4y ago

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system with…

▾ Abyssalemerson · dixell_xweb-500_firmwareEPSS 18%via NVD
CVE-2021-46354High· 7.5PoC
4y ago

Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site

Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable…

▾ Midnightcybelesoft · thinfinity_virtualuiEPSS 13%via NVD
CVE-2021-42641High· 7.5
4y ago

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.

▾ Twilightprinterlogic · web_stackEPSS 2.0%via NVD
CVE-2021-42640Critical· 9.1
4y ago

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.

▾ Midnightprinterlogic · web_stackEPSS 2.0%via NVD
CVE-2021-40639High· 7.5
5y ago

Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.

Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.

▾ Twilightjflyfox · jfinal_cmsEPSS 1.2%via NVD
CVE-2020-26868High· 7.5
5y ago

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affect…

▾ Twilightarcinformatique · pcvueEPSS 2.2%via NVD
CVE-2020-3315Medium· 5.3
6y ago

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors i…

▾ Sunlitcisco · secure_firewall_management_centerEPSS 2.2%via NVD
CWE-668 vulnerabilities (CVEs) — page 2 · VulnSea