VulnSea

CWE-704

CVEs classified under CWE-704, newest first.

19 CVEsRSS

CVE-2026-20249High· 8.6
5d ago

A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software coul…

A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software coul…

TwilightCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.40%via NVD
CVE-2026-86348Medium· 4.3
1w ago

Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.

Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.. Mattermost Advisory ID: MMSA…

SunlitMattermost · MattermostEPSS 0.22%via NVD
CVE-2026-87546Medium· 4.3
1w ago

Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted file

Incorrect type conversion or cast in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Low)

Sunlitgoogle · chromeEPSS 0.20%via NVD
CVE-2026-28609High· 8.8PoC
1w ago

In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting

In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Midnightgoogle · androidEPSS 0.28%via NVD
CVE-2026-58822Critical· 9.8
1w ago

In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting

In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

MidnightGoogle · AndroidEPSS 0.31%via NVD
CVE-2026-69585High· 7.8
1w ago

Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.36%via NVD
CVE-2026-50278Medium· 6.5
1mo ago

iccDEV provides a set of libraries and tools for working with ICC color management profiles

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing I…

SunlitEPSS 0.25%via NVD
CVE-2026-15826Critical· 9.8PoC
1mo ago

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_i…

AbyssalEPSS 3.9%via NVD
CVE-2026-73429Medium· 5.3
1mo ago

Russh is a Rust SSH client & server library

Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ephemeral value that is not 32 bytes long. The client-side Curve255…

Sunlitrussh · russhEPSS 0.35%via NVD
CVE-2026-6726High· 7.9
1mo ago

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key…

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key…

TwilightEPSS 0.21%via NVD
GHSA-g9hv-x236-4qp3Medium· 5.3
1mo ago

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

Sunlitrussh · russhvia GHSA
CVE-2026-50337High· 7.8
2mo ago

Windows Notification Elevation of Privilege Vulnerability

Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-59871Medium· 5.3
2mo ago

node-tar: node-tar: Denial of Service due to incorrect PAX path handling (CVE-2026-59871)

A flaw was found in node-tar, a library for manipulating tar archives in Node.js. This vulnerability occurs when the library incorrectly converts specific archive path values into numbers, leading to an error during subsequent path process…

SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.64%via CSAF
CVE-2026-55076High· 7.4
2mo ago

Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

Twilightcoder · github.com/coder/coder/v2EPSS 0.61%via GHSA
CVE-2026-46597High· 7.5
4mo ago

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh

Twilightx · golang.org/x/cryptoEPSS 0.47%via OSV
CVE-2026-44223Medium· 6.5
4mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step,…

SunlitRed Hat · Red Hat Enterprise Linux AI 3.4EPSS 0.37%via NVD
CVE-2025-1057Medium· 4.3
1y ago

A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries created by previous versions, for example, 7.11.0

A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries created by previous versions, for example, 7.11.0. Specifically, old…

SunlitEPSS 0.39%via NVD
CVE-2023-0286High· 7.4
3y ago

openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)

A type confusion vulnerability was found in OpenSSL when OpenSSL X.400 addresses processing inside an X.509 GeneralName. When CRL checking is enabled (for example, the application sets the X509_V_FLAG_CRL_CHECK flag), this vulnerability ma…

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 60%via CSAF
CVE-2020-25576Critical· 9.8
6y ago

An issue was discovered in the rand_core crate before 0.4.2 for Rust

An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.

Midnightrust-random · randEPSS 1.6%via NVD
CWE-704 vulnerabilities (CVEs) · VulnSea