VulnSea

CWE-669

CVEs classified under CWE-669, newest first.

23 CVEsRSS

CVE-2026-92952Medium· 6.8PoC
4d ago

vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary

vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks and write traps in lib/bridge.js use…

Twilightpatriksimek · vm2EPSS 0.42%via NVD
CVE-2026-20194Critical· 9.1
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal secur…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal secur…

MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 0.45%via NVD
CVE-2026-38924Low· 2.9PoC
1w ago

In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0

In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a "potential security hazard" but the Serena documentation, at the time of the issue report prop…

TwilightOraios AI · SerenaEPSS 0.12%via NVD
CVE-2023-37252Low· 3.1PoC
1w ago

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.

TwilightMediaWiki · CheckUserEPSS 0.20%via NVD
CVE-2026-25832Low· 3.7
1w ago

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

SunlitTrustedFirmware · Mbed TLSEPSS 0.22%via NVD
CVE-2023-37253Low· 3.1PoC
1w ago

An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3

An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.

TwilightMediaWiki · ProofreadPageEPSS 0.20%via NVD
CVE-2023-32803High· 7.5
1w ago

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23…

TwilightAmazon · ca-certificatesEPSS 0.18%via NVD
CVE-2025-45480Low· 3.0
1w ago

Floodlight 71fe8a7 allows disruption of host communication via link spoofing

Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.

Sunlitprojectfloodlight · FloodlightEPSS 0.15%via NVD
CVE-2026-89162Low· 2.9
1w ago

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

Sunlitpcre · pcre2EPSS 0.11%via NVD
CVE-2026-87724Medium· 6.5
1w ago

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.

Sunlittorprject · TorEPSS 0.26%via NVD
CVE-2026-86144Medium· 5.6
2w ago

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses th…

Sunlitxmlsoft · libxml2EPSS 0.18%via NVD
CVE-2026-75003Medium· 5.8
1mo ago

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

Sunlitroundcube · webmailEPSS 0.39%via NVD
CVE-2026-75000Medium· 5.8
1mo ago

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

Sunlitroundcube · webmailEPSS 0.35%via NVD
CVE-2026-75010Medium· 6.4
1mo ago

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube inst…

Sunlitroundcube · webmailEPSS 0.29%via NVD
CVE-2026-73574Low· 3.1
1mo ago

In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter

In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability…

SunlitEPSS 0.20%via NVD
CVE-2026-71194Medium· 6.8
1mo ago

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic e…

SunlitEPSS 0.30%via NVD
CVE-2026-73281Low· 3.5
1mo ago

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bin…

Sunlitopenbsd · opensshEPSS 0.16%via NVD
CVE-2026-46448Medium· 5.4
3mo ago

OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints

OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints

Sunlitnova · novaEPSS 0.27%via OSV
CVE-2026-42997High· 7.7
4mo ago

An issue was discovered in idrac in OpenStack Ironic before 35.0.1

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides…

Twilightopenstack · ironicEPSS 0.43%via NVD
CVE-2026-31431High· 7.8CISA KEVPoC
5mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in op…

Abyssalredhat · openshift_container_platformEPSS 100%via NVD
CVE-2026-24708High· 8.2
7mo ago

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1

An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend t…

TwilightOpenStack · NovaEPSS 0.38%via NVD
CVE-2021-30120Critical· 9.9⚠ Exploited
5y ago

Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement

Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed de…

Abyssalkaseya · vsaEPSS 5.7%via NVD
CVE-2020-1048High· 7.8PoC
6y ago

An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system

An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevate…

Midnightmicrosoft · windows_10EPSS 16%via NVD
CWE-669 vulnerabilities (CVEs) · VulnSea