VulnSea

CWE-755

CVEs classified under CWE-755, newest first.

36 CVEsRSS

CVE-2026-63450Low· 3.7
3d ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 8.0.6, the FTP parser in src/app-layer-ftp.c treats a RETR or STOR command sent before PORT or PASV negotiatio…

SunlitOISF · suricataEPSS 0.24%via NVD
CVE-2026-54580High· 8.3
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures t…

TwilightMidnightBSD · mportEPSS 0.25%via NVD
CVE-2026-54578Low· 2.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than …

SunlitMidnightBSD · mportEPSS 0.11%via NVD
CVE-2026-81516High· 7.5
4d ago

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, ConsulDiscoveryClient constructs ConsulServiceInstance objects by parsing each registrat…

TwilightSteeltoeOSS · security-advisoriesEPSS 0.34%via NVD
CVE-2026-81515High· 7.5
4d ago

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, EurekaDiscoveryClient deserializes the registry response as one unit, and an unrecognize…

TwilightSteeltoeOSS · security-advisoriesEPSS 0.34%via NVD
CVE-2026-53459Critical· 9.3
6d ago

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flood…

Midnightmaziggy · bambuddyEPSS 0.42%via NVD
CVE-2026-89025High· 7.5
6d ago

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content

Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request t…

TwilightBelden · Hirschmann HiOS Switch PlatformEPSS 0.42%via NVD
CVE-2026-54632High· 7.5
1w ago

SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET

SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted b…

Twilightsipsorcery-org · sipsorceryEPSS 0.54%via NVD
CVE-2026-53496Medium· 5.3PoC
1w ago

ExifReader is a JavaScript Exif information parser

ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where f…

Twilightmattiasw · ExifReaderEPSS 0.45%via NVD
CVE-2026-45819High· 7.5
1mo ago

baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.

baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.

TwilightRed Hat · Red Hat Ceph Storage 9EPSS 0.37%via NVD
GHSA-jwjp-4649-v8jpHigh· 7.5
1mo ago

SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing

TwilightSIPSorcery · SIPSorceryvia GHSA
GHSA-pfvm-w89x-94jwHigh· 7.5
1mo ago

SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)

SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)

TwilightSIPSorcery · SIPSorceryvia GHSA
CVE-2026-52856High· 7.5
1mo ago

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

Twilightpterodactyl · github.com/pterodactyl/wingsEPSS 0.34%via NVD
CVE-2026-16730Medium· 5.5
1mo ago

A flaw was found in dbus-broker

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open ma…

SunlitRed Hat · dbus-brokerEPSS 0.11%via NVD
CVE-2026-59952Medium
1mo ago

Valibot: record() issue paths can make flatten() throw for inherited Object property names

Valibot: record() issue paths can make flatten() throw for inherited Object property names

Sunlitvalibot · valibotEPSS 0.30%via GHSA
CVE-2026-59162High· 7.5
2mo ago

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice,…

Twilightexcelize · excelizeEPSS 0.39%via NVD
CVE-2026-35339Medium· 5.5
2mo ago

chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)

chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)

Sunlituu_chmod · uu_chmodEPSS 0.14%via GHSA
CVE-2026-54775Medium· 6.5
3mo ago

CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.

CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.

SunlitCoreWCF · CoreWCF.KafkaEPSS 0.60%via GHSA
CVE-2026-48524Low· 3.7
3mo ago

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

Sunlitpyjwt · pyjwtEPSS 0.36%via OSV
CVE-2026-48036High
3mo ago

@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

Twilighthulumi · @hulumi/driftEPSS 0.29%via GHSA
CVE-2026-49235High
3mo ago

Routinator crashes when encountering maliciously crafted RRDP XML files

Routinator crashes when encountering maliciously crafted RRDP XML files

Twilightroutinator · routinatorEPSS 0.37%via GHSA
CVE-2024-53063High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: prevent the risk of out of memory access The dvbdev contains a static variable used to store dvb minors. The behavior of it depends if CONFIG_DVB_DYNAM…

In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: prevent the risk of out of memory access The dvbdev contains a static variable used to store dvb minors. The behavior of it depends if CONFIG_DVB_DYNAM…

Twilightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2024-51744Low· 3.1
1y ago

golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt (CVE-2024-517…

A flaw was found in the golang-jwt package. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are not checking errors in the way they should be. Especially, if a token is both expired and in…

SunlitRed Hat · Red Hat OpenShift Container Platform 4.16EPSS 0.51%via CSAF
CVE-2024-6594High· 7.5
1y ago

Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands

Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denia…

Twilightwatchguard · single_sign-on_clientEPSS 0.63%via NVD
CVE-2024-26584Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt…

In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt…

Midnightlinux · linux_kernelEPSS 0.75%via NVD
CVE-2024-21907High· 7.5PoC
2y ago

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial…

Midnightnewtonsoft · json.netEPSS 33%via NVD
CVE-2023-48232Low· 3.9
2y ago

Vim is an open source command line text editor

Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset for overlong lines and smooth scrolling is enabled and the cpo-settings include the 'n' flag. This may happen when a wi…

Sunlitvim · vimEPSS 0.67%via NVD
CVE-2023-5090Medium· 6.0
2y ago

A flaw was found in KVM

A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition.

Sunlitlinux · linux_kernelEPSS 0.23%via NVD
CVE-2023-28840High· 7.5
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

Twilightmobyproject · mobyEPSS 2.6%via NVD
CVE-2023-28841Medium· 6.8
3y ago

Moby is an open source container framework developed by Docker Inc

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as m…

Sunlitmobyproject · mobyEPSS 0.69%via NVD
CWE-755 vulnerabilities (CVEs) · VulnSea