VulnSea

CWE-682

CVEs classified under CWE-682, newest first.

16 CVEsRSS

CVE-2026-20335High· 8.1
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software en…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software en…

TwilightCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.28%via NVD
CVE-2026-86736Medium· 4.3
1w ago

snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requ…

snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requ…

Sunlitsnipeitapp · snipe-itEPSS 0.18%via NVD
CVE-2026-53706None
2w ago

PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer

PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the prevail eBPF verifier accepts ALU32 ADD and SUB instructions that operate on pointer-typed registers without checking the i…

SunlitEPSS 0.29%via NVD
CVE-2026-53670None
2w ago

PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer

PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently skips offset-variable updates when the destination register carri…

SunlitEPSS 0.29%via NVD
CVE-2026-20275High· 8.8
2w ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases tha…

TwilightCisco · Cisco IOS XR SoftwareEPSS 0.19%via NVD
CVE-2026-53671None
2w ago

PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer

PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_CTX-typed base register as a silent no-op: do_mem_store in src/cr…

SunlitEPSS 0.29%via NVD
CVE-2026-54754Critical· 9.6
3w ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPer…

Midnightklever-io · github.com/klever-io/klever-goEPSS 0.30%via NVD
CVE-2026-71479Critical· 9.1
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio…

MidnightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.52%via NVD
CVE-2026-20270High· 8.6
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

Twilightcisco · ios_xeEPSS 0.28%via NVD
CVE-2026-10773Medium· 5.4
1mo ago

The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faulty bounds check

The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faulty bounds check. The guard used msg_type <= sizeof(name) instead of msg_type <= ARRAY_SI…

SunlitEPSS 0.28%via NVD
GHSA-464c-974j-9xm6Low· 3.3
1mo ago

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

AWS CDK CodeBuild S3 Log Encryption Boolean Inversion

Sunlitaws-cdk-lib · aws-cdk-libvia OSV
CVE-2026-55597Medium· 5.5
1mo ago

ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments

ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments

SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.15%via GHSA
CVE-2023-7346Medium· 4.0
4mo ago

Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: f…

Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: f…

SunlitEPSS 0.14%via NVD
CVE-2026-33487High· 7.5PoC
5mo ago

goxmlsig provides XML Digital Signatures implemented in Go

goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID.…

Midnightgoxmldsig_project · goxmldsigEPSS 0.30%via NVD
CVE-2025-5372Medium· 5.0
1y ago

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate f…

Sunlitlibssh · libsshEPSS 0.43%via NVD
CVE-2025-4435High· 7.5
1y ago

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that …

TwilightEPSS 0.59%via NVD
CWE-682 vulnerabilities (CVEs) · VulnSea