VulnSea

CWE-754

CVEs classified under CWE-754, newest first.

50 CVEsRSS

CVE-2026-73549Medium· 5.3
today

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address paths reconstruct scoped IPv6 addres…

Sunlitenvoyproxy · envoyvia NVD
CVE-2026-94105Medium· 5.3
yesterday

NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to disable password recovery by supplying an invalid code parameter

NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to disable password recovery by supplying an invalid code parameter. Attackers c…

Sunlitnivocart · nivocartEPSS 0.25%via NVD
CVE-2026-93387Medium· 4.3
4d ago

Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page

Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-77411Critical· 9.5
5d ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared AMQP longstr length exceeds 0x7FFFFFFF instead of returning ErrSyntax. The function leaves the…

Midnightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-91733High· 8.3
6d ago

Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page

Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.32%via NVD
CVE-2026-65838High· 8.2
1w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass …

Twilightzalando · skipperEPSS 0.27%via NVD
CVE-2026-13417Medium· 4.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash th…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash th…

SunlitMattermost · MattermostEPSS 0.21%via NVD
CVE-2026-10556Medium· 5.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft…

SunlitMattermost · MattermostEPSS 0.25%via NVD
CVE-2026-87012Medium· 4.3
1w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the share…

Sunlitopenwebui · open_webuiEPSS 0.28%via NVD
CVE-2026-87645Medium· 5.4
1w ago

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.17%via NVD
CVE-2026-87548Medium· 4.3
1w ago

Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page

Improper state validation in Installer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.28%via NVD
CVE-2026-87532Medium· 6.5
1w ago

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.21%via NVD
CVE-2026-87656Medium· 5.4
1w ago

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

Sunlitgoogle · chromeEPSS 0.17%via NVD
CVE-2026-73314High· 7.5PoC
1w ago

XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_…

XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_…

Midnightxenforo · xenforoEPSS 0.45%via NVD
CVE-2026-85014Medium· 5.9
2w ago

undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake

undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the wri…

Sunlitnodejs · undiciEPSS 0.37%via NVD
CVE-2026-56812Medium
2w ago

Phoenix: Presence keys colliding with `Object.prototype` members break existence checks

Phoenix: Presence keys colliding with `Object.prototype` members break existence checks

Sunlitphoenix · phoenixEPSS 0.51%via GHSA
CVE-2026-55484High· 7.5
3w ago

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning wi…

Twilightguno1928 · github.com/guno1928/alos-httpEPSS 0.34%via NVD
CVE-2026-75595Critical· 7.4
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so…

Midnightnetty · io.netty:netty-handlerEPSS 0.32%via NVD
CVE-2026-73288Medium· 6.1
1mo ago

RustFS is a distributed object storage system built in Rust

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle…

Sunlitrustfs · rustfsEPSS 0.24%via NVD
CVE-2026-73429Medium· 5.3
1mo ago

Russh is a Rust SSH client & server library

Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ephemeral value that is not 32 bytes long. The client-side Curve255…

Sunlitrussh · russhEPSS 0.35%via NVD
CVE-2026-73430Medium· 5.3
1mo ago

Russh is a Rust SSH client & server library

Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH_INIT with a 32-byte all-zero Q_C value. Curve25519Kex::server_dh in russh/src/kex/curve…

Sunlitrussh · russhEPSS 0.33%via NVD
CVE-2026-66774Low· 3.7
1mo ago

SAP Approuter does not consistently handle certain error conditions

SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the…

Sunlitsap · approuterEPSS 0.22%via NVD
CVE-2025-71413Medium· 5.3
1mo ago

Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced situational awareness

Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced situational awareness. This type of attack can be carried out remot…

SunlitEPSS 0.20%via NVD
CVE-2025-71412High· 7.1
1mo ago

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can…

TwilightEPSS 0.18%via NVD
CVE-2026-69185High· 7.5
1mo ago

Socket.IO enables bidirectional and low-latency communication for every platform

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, w…

Twilightsocket.io-parser · socket.io-parserEPSS 0.50%via NVD
CVE-2026-20486None
1mo ago

In imgsensor, there is a possible application crash due to incorrect error handling

In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for expl…

SunlitEPSS 0.11%via NVD
GHSA-5xvq-cp9x-6p6rMedium· 5.3
1mo ago

Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)

Sunlitrussh · russhvia GHSA
GHSA-g9hv-x236-4qp3Medium· 5.3
1mo ago

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)

Sunlitrussh · russhvia GHSA
CVE-2026-57031Medium· 4.7
2mo ago

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters. On MX Series device…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters. On MX Series device…

Sunlitjuniper · junosEPSS 0.22%via NVD
CVE-2026-33794Medium· 5.9
2mo ago

An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating con…

An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating con…

Sunlitjuniper · junos_os_evolvedEPSS 0.40%via NVD
CWE-754 vulnerabilities (CVEs) · VulnSea