VulnSea

CWE-799

CVEs classified under CWE-799, newest first.

10 CVEsRSS

CVE-2026-93650Low· 3.7PoC
4d ago

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of…

TwilightEPSS 0.55%via NVD
CVE-2025-36045Medium· 4.3
4d ago

IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service due to improper control of interaction frequency.

SunlitIBM · TS4300EPSS 0.26%via NVD
CVE-2025-13882Medium· 5.3
4d ago

IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to …

IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to …

SunlitIBM · Sterling Partner Engagement Manager Essentials EditionEPSS 0.42%via NVD
CVE-2026-54594Medium· 5.3PoC
5d ago

OmniBlocks is a monorepo for the OmniBlocks project

OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenev…

TwilightOmniBlocks · monorepoEPSS 0.33%via NVD
CVE-2026-85586Medium· 6.9
2w ago

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing da…

Sunlitthorsten · phpMyFAQEPSS 0.36%via NVD
CVE-2026-54738Medium· 6.5
1mo ago

Lemmy is a link aggregator and forum for the fediverse

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src…

SunlitEPSS 0.43%via NVD
CVE-2026-19898Low· 3.7
1mo ago

A vulnerability was found in VictoriaMetrics up to 1.146.0

A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing a manipulation results in improper restriction…

SunlitEPSS 0.48%via NVD
CVE-2026-19897Low· 3.7
1mo ago

A vulnerability has been found in mangroup dtale up to 3.22.0

A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login Endpoint. Such manipulation leads to improper restriction of excessive authentication a…

SunlitEPSS 0.37%via NVD
CVE-2026-19895Low· 3.7
1mo ago

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restrict…

SunlitEPSS 0.40%via NVD
CVE-2026-33434Medium· 4.3
2mo ago

Wazuh is a free and open source platform used for threat prevention, detection, and response

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimitsMiddleware.dispatch() causes the /events endpoint rate check to u…

SunlitEPSS 0.40%via NVD
CWE-799 vulnerabilities (CVEs) · VulnSea