VulnSea

CWE-672

CVEs classified under CWE-672, newest first.

13 CVEsRSS

CVE-2026-55250High· 8.7
2w ago

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-perf…

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-perf…

Twilightmacropay-solutions · maravel-frameworkEPSS 0.55%via NVD
CVE-2026-53637Medium· 6.5
2w ago

Sylius is an Open Source eCommerce Framework on Symfony

Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is co…

SunlitSylius · SyliusEPSS 0.29%via NVD
CVE-2026-61699High· 8.1PoC
2w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches an…

Midnightforgekeep · nebula-meshEPSS 0.25%via NVD
CVE-2026-85044Medium· 6.5
2w ago

Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page

Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.23%via NVD
CVE-2026-19538High· 7.5
3w ago

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

Twilightnlnetlabs · nsdEPSS 0.30%via NVD
CVE-2026-44725Medium· 6.6
1mo ago

EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles

EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, the plugin-install REST API and dashboard upload accepted stale grants created with …

SunlitEPSS 0.25%via NVD
CVE-2026-50575High· 7.7
1mo ago

BetterDesk is a remote desktop management solution

BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Ve…

TwilightEPSS 0.21%via NVD
CVE-2026-52733Medium· 6.5
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/…

Sunlitzebra-state · zebra-stateEPSS 0.34%via NVD
GHSA-2vg6-77g8-24mpLow· 3.8
2mo ago

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

Better Auth: Stale sessions persist after user deletion across admin, anonymous, and SCIM flows

Sunlitbetter-auth · better-authvia GHSA
CVE-2026-58291Medium· 6.1
2mo ago

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.99%via CVEORG
GHSA-pw6j-qg29-8w7fMedium· 5.9
3mo ago

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

Sunlittornado · tornadovia OSV
CVE-2026-23111High· 7.8PoC
7mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() nft_map_catchall_activate() has an inverted element activity check compared to its non-…

Midnightlinux · linux_kernelEPSS 0.49%via NVD
CVE-2021-47069High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry do_mq_timedreceive calls wq_sleep with a stack local address

In the Linux kernel, the following vulnerability has been resolved: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry do_mq_timedreceive calls wq_sleep with a stack local address. The sender (do_mq_timedsend) us…

Twilightlinux · linux_kernelEPSS 0.26%via NVD
CWE-672 vulnerabilities (CVEs) · VulnSea