VulnSea

CWE-757

CVEs classified under CWE-757, newest first.

9 CVEsRSS

CVE-2026-89177High· 8.8
1w ago

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmit…

TwilightHowyar · WeenyGeniusEPSS 0.23%via NVD
CVE-2026-18691High· 8.8
1mo ago

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, t…

Twilightmongodb · mongodbEPSS 0.23%via NVD
CVE-2026-55953High· 7.4
1mo ago

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler…

Twilighterlang · erlang/otpEPSS 0.23%via NVD
CVE-2026-54291High
2mo ago

PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms

PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms

Twilightpostgresql · org.postgresql:postgresqlEPSS 0.24%via GHSA
GHSA-9h47-pqcx-hjr4High· 8.7
2mo ago

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default

Twilightbetter-auth · better-authvia GHSA
CVE-2026-53712High
2mo ago

OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms

OnGres SCRAM silent channel-binding authentication downgrade via unsupported certificate algorithms

Twilightongres · com.ongres.scram:scram-clientEPSS 0.26%via GHSA
CVE-2026-54780Low· 3.7
3mo ago

CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass

CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass

SunlitCoreWCF · CoreWCF.PrimitivesEPSS 0.24%via GHSA
CVE-2026-48747Medium
3mo ago

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

Sunlitsymfony · symfony/mailomat-mailerEPSS 0.25%via GHSA
CVE-2026-1677Medium· 5.3
4mo ago

Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol selection is not propagated to mbedTLS (e.g

Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol selection is not propagated to mbedTLS (e.g. via `mbedtls_ssl_conf_mi…

Sunlitzephyrproject · zephyrEPSS 0.24%via NVD
CWE-757 vulnerabilities (CVEs) · VulnSea