VulnSea

CWE-693

CVEs classified under CWE-693, newest first.

276 CVEsRSS

CVE-2026-5900Medium· 4.3
5mo ago

Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page

Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-5896Medium· 6.1
5mo ago

Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass sandbox download restrictions via a crafted HTML page

Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass sandbox download restrictions via a crafted HTML page. (Chromium security severity:…

▾ Sunlitgoogle · chromeEPSS 0.22%via NVD
CVE-2026-27893High· 8.8
6mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the…

▾ Twilightvllm · vllmEPSS 1.8%via NVD
CVE-2026-56315Critical· 9.8
6mo ago

PickleScan has multiple stdlib modules with direct RCE not in blocklist

PickleScan has multiple stdlib modules with direct RCE not in blocklist

▾ Midnightpicklescan · picklescanEPSS 1.1%via OSV
CVE-2026-0012Medium· 6.2
6mo ago

In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code

In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User inter…

▾ Sunlitgoogle · androidEPSS 0.11%via NVD
CVE-2026-0011High· 8.4
6mo ago

In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code

In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed…

▾ Twilightgoogle · androidEPSS 0.13%via NVD
CVE-2026-20824Medium· 5.5
8mo ago

Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.87%via NVD
CVE-2026-0881Critical· 10.0
8mo ago

Sandbox escape in the Messaging System component

Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

▾ Midnightmozilla · firefoxEPSS 0.36%via NVD
CVE-2026-0877High· 8.1
8mo ago

Mitigation bypass in the DOM: Security component

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

▾ Twilightmozilla · firefoxEPSS 0.48%via NVD
CVE-2025-69264High· 8.8PoC
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". Wh…

▾ Midnightpnpm · pnpmEPSS 1.0%via NVD
CVE-2025-46291High· 7.8
9mo ago

A logic issue was addressed with improved validation

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An app may bypass Gatekeeper checks.

▾ Twilightapple · macosEPSS 0.20%via NVD
CVE-2025-46281High· 8.8
9mo ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to break out of its sandbox.

▾ Twilightapple · macosEPSS 0.20%via NVD
CVE-2025-65318Critical· 9.1PoC
9mo ago

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS…

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS…

▾ Abyssalcanarymail · canary_mailEPSS 0.56%via NVD
CVE-2025-67460High· 7.8
9mo ago

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.

▾ Twilightzoom · roomsEPSS 0.16%via NVD
CVE-2025-10157High· 7.8
1y ago

A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check

A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check. This is possible because the scanner performs an exact match for modul…

▾ Twilightmmaitre314 · picklescanEPSS 0.79%via NVD
CVE-2025-9866High· 8.8
1y ago

Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page

Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.36%via NVD
CVE-2024-56182High· 8.2
1y ago

A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (…

A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (…

▾ TwilightSiemens · SIMATIC Field PG M5EPSS 0.21%via NVD
CVE-2024-56181High· 8.2
1y ago

A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (A…

A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (A…

▾ TwilightSiemens · SIMATIC Field PG M5EPSS 0.21%via NVD
CVE-2024-11734Medium· 6.5
1y ago

A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service

A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting ne…

▾ SunlitEPSS 0.95%via NVD
CVE-2024-30052Medium· 4.7PoC
2y ago

Visual Studio Remote Code Execution Vulnerability

Visual Studio Remote Code Execution Vulnerability

▾ Twilightmicrosoft · visual_studio_2019EPSS 1.4%via NVD
CVE-2024-0682Medium· 5.3
2y ago

The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5

The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin not properly restricting access to posts via the REST API when a page has been made pri…

▾ Sunlitsivel · page_restrictEPSS 0.50%via NVD
CVE-2023-4039Medium· 4.8
3y ago

**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being d…

**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being d…

▾ Sunlitgnu · gccEPSS 0.76%via NVD
CVE-2021-1224Medium· 5.8
5y ago

Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP

Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. T…

▾ Sunlitcisco · secure_firewall_management_centerEPSS 2.0%via NVD
CVE-2021-1223High· 7.5
5y ago

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an …

▾ Twilightcisco · secure_firewall_management_centerEPSS 2.0%via NVD
CVE-2020-3458Medium· 6.7
5y ago

Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authent…

Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authent…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.32%via NVD
CVE-2020-3299Medium· 5.8
5y ago

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HTTP

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured File Policy for HTTP. The vulnerability is due to incorrect detection of mo…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 2.3%via NVD
CVE-2020-3315Medium· 5.3
6y ago

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors i…

▾ Sunlitcisco · secure_firewall_management_centerEPSS 2.2%via NVD
CVE-2020-3285Medium· 5.8
6y ago

A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured TLS 1.3…

A vulnerability in the Transport Layer Security version 1.3 (TLS 1.3) policy with URL category functionality for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured TLS 1.3…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 1.5%via NVD
CVE-2019-1970Medium· 5.8
7y ago

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured file po…

A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol inspection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the configured file po…

▾ Sunlitcisco · secure_firewall_management_centerEPSS 1.5%via NVD
CVE-2019-1669High· 8.6
7y ago

A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) cond…

A vulnerability in the data acquisition (DAQ) component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access control policies or cause a denial of service (DoS) cond…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 1.2%via NVD
CWE-693 vulnerabilities (CVEs) — page 9 · VulnSea