VulnSea

CWE-778

CVEs classified under CWE-778, newest first.

6 CVEsRSS

CVE-2026-92002Medium· 5.1
6d ago

Affected versions of MISP use Redis to throttle repeated authentication-failure log entries

Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity. However, User->setupRedis() returns fals…

SunlitMISP · MISPEPSS 0.39%via NVD
CVE-2026-91859Medium· 5.3
6d ago

Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time

Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a re…

SunlitMISP · MISPEPSS 0.30%via NVD
CVE-2026-90955Medium· 4.6
1w ago

Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID

Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLoga…

SunlitMISP · MISPEPSS 0.11%via NVD
CVE-2026-29812Medium· 4.3
1w ago

CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

SunlitCyberPanel · CyberPanelEPSS 0.22%via NVD
CVE-2026-66816Medium· 6.5
1w ago

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

Sunlitmicrosoft · sql_server_2022EPSS 0.71%via NVD
CVE-2020-37268Medium· 6.3
4w ago

Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type

Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in a module type. Applying a functor inlines the body of the parameter…

SunlitEPSS 0.12%via NVD
CWE-778 vulnerabilities (CVEs) · VulnSea