VulnSea

CWE-791

CVEs classified under CWE-791, newest first.

6 CVEsRSS

CVE-2026-92018Critical· 9.6⚖ disputed
1w ago

Sandbox escape in the DOM: Core & HTML component

Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.35%via NVD
CVE-2026-86206Medium· 6.9PoC
2w ago

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

TwilightN-able · N-centralEPSS 0.68%via NVD
CVE-2026-75979Medium· 6.3
1mo ago

A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta

A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerController.java of the component SQL Preview Endpoint. The manipulation of the argument sq…

SunlitEPSS 0.30%via NVD
CVE-2026-19929Medium· 6.3
1mo ago

A vulnerability was identified in OpenBoxes up to 0.9.6

A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Template Processing. The manipulat…

SunlitEPSS 0.28%via NVD
CVE-2026-11998High· 7.6
3mo ago

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose is to …

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose is to …

TwilightEPSS 0.50%via NVD
CVE-2024-39283Medium· 6.0
2y ago

Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access.

Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access.

Sunlitintel · tdx_moduleEPSS 0.18%via NVD
CWE-791 vulnerabilities (CVEs) · VulnSea