VulnSea

CWE-670

CVEs classified under CWE-670, newest first.

16 CVEsRSS

CVE-2026-92932Medium· 5.1
5d ago

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] &…

Sunlitmisp · sachertortephpEPSS 0.23%via NVD
CVE-2026-73468Medium· 6.5
6d ago

A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.

A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.

SunlitArista Networks · EOSEPSS 0.25%via NVD
CVE-2026-55624None
4w ago

MintyItanium Lost-Auction is an auction plugin for Minecraft

MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blocks or duplicate items from the GUI. Commit 88c920b05042929db334ba06d57f052b42…

SunlitEPSS 0.24%via NVD
CVE-2026-72705Medium· 6.3
4w ago

The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments

The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass itself as a higher-order argument to a second fixpoint, which then applies it to a value that is not a subterm …

SunlitEPSS 0.12%via NVD
CVE-2026-72704Medium· 6.3
4w ago

The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by transport

The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by transport. A fixpoint may apply a rewrite along an equality between types to its …

SunlitEPSS 0.12%via NVD
CVE-2026-72703Medium· 6.3
4w ago

The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that fixpoint

The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that fixpoint. find_uniform_parameters in kernel/inductive.ml inspects only self-recursive…

SunlitEPSS 0.12%via NVD
CVE-2026-73283Low· 2.5⚖ disputed
1mo ago

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

Sunlitopenbsd · opensshEPSS 0.09%via NVD
CVE-2026-14935Low· 3.7
2mo ago

Gstreamer1-plugins-bad-free: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check

A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attrib…

SunlitRed Hat · gstreamer1-plugins-bad-freeEPSS 0.23%via CVEORG
CVE-2026-35343Low· 3.3
2mo ago

cut: -s (only-delimited) ignored when delimiter is a newline

cut: -s (only-delimited) ignored when delimiter is a newline

Sunlituu_cut · uu_cutEPSS 0.14%via GHSA
CVE-2026-7656High· 8.1
2mo ago

The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 4861 validity checks with the ICMPv6 code check using the wro…

The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 4861 validity checks with the ICMPv6 code check using the wro…

Twilightzephyrproject · zephyrEPSS 0.33%via NVD
CVE-2026-55276Critical· 9.1
2mo ago

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.…

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.…

Midnightapache · tomcatEPSS 0.56%via NVD
CVE-2026-53404High· 7.3
2mo ago

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0…

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0…

Twilightapache · tomcatEPSS 0.62%via NVD
CVE-2026-20171Medium· 6.8
4mo ago

A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to …

A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to …

SunlitEPSS 0.47%via NVD
CVE-2026-41988Low· 3.2
5mo ago

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.

Sunlituuidjs · uuidEPSS 0.18%via NVD
CVE-2023-41052Medium· 5.3
3y ago

incorrect order of evaluation of side effects for some builtins

incorrect order of evaluation of side effects for some builtins

Sunlitvyper · vyperEPSS 0.54%via OSV
CVE-2021-1236Medium· 5.3
5y ago

Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system

Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a…

Sunlitcisco · secure_firewall_management_centerEPSS 2.1%via NVD
CWE-670 vulnerabilities (CVEs) · VulnSea