VulnSea

CWE-807

CVEs classified under CWE-807, newest first.

43 CVEsRSS

CVE-2026-85751Critical· 9.8
today

Mailu is a mail server distributed as a set of Docker images

Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-F…

MidnightMailu · Mailuvia NVD
CVE-2026-87858High· 7.2
today

Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header

Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could attach a completion callback whose UR…

TwilightTemporal Technologies, Inc. · go.temporal.io/servervia NVD
CVE-2026-81179High· 8.1
3d ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a…

TwilightSyslifters · sysreptorEPSS 0.26%via NVD
CVE-2026-86863Critical· 9.8
4d ago

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment

pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEB…

Midnightpgadmin · pgadmin_4EPSS 0.36%via NVD
CVE-2026-92949Medium· 4.0PoC
4d ago

vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections

vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() protections. Attackers can use Object.getOwnPropertyDescr…

Twilightpatriksimek · vm2EPSS 0.25%via NVD
CVE-2026-78427Medium· 4.3
4d ago

The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images

The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any…

Sunlitgo · github.com/neuvector/neuvectorEPSS 0.36%via NVD
CVE-2026-92079Low· 3.4
6d ago

Mitigation bypass in the Widget: Win32 component

Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.15%via NVD
CVE-2026-92074Low· 3.4
6d ago

Mitigation bypass in the Popup Blocker component

Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-92019High· 8.1
6d ago

Mitigation bypass in the Remote Settings Client component

Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.17%via NVD
CVE-2026-92030Medium· 5.4
6d ago

Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component

Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-92038Critical· 9.1
6d ago

Mitigation bypass in the Remote Settings Client component

Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-92041Critical· 9.1⚖ disputed
6d ago

Mitigation bypass in the DOM: Networking component

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-59157Medium· 6.5
6d ago

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParam…

Sunlitncarlier · webhookdEPSS 0.46%via NVD
CVE-2026-79701Medium· 6.9
1w ago

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the resul…

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the resul…

Sunlitjoomshaper.com · SP Page Builder (Pro) extension for JoomlaEPSS 0.27%via NVD
CVE-2026-79700Medium· 6.9
1w ago

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag f…

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag f…

Sunlitjoomshaper.com · SP Page Builder (Pro) extension for JoomlaEPSS 0.27%via NVD
CVE-2026-88004High· 7.4
1w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing a…

Twilighttraefik · traefikEPSS 0.27%via NVD
CVE-2026-87479High· 8.3
1w ago

Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the s…

Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the s…

Twilightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-82533Critical· 9.6
1w ago

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the a…

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the a…

MidnightDeepSeek · DeepSeek HarnessEPSS 0.62%via NVD
CVE-2026-66768Critical· 9.0
1w ago

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger…

MidnightSAP_SE · SAP NetWeaver (SAP GUI for Java)EPSS 0.32%via NVD
CVE-2026-85602Medium· 5.3
2w ago

The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload

The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, a…

SunlitEPSS 0.26%via NVD
CVE-2026-54730None
1mo ago

authentik is an open-source identity provider

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise…

SunlitEPSS 0.37%via NVD
CVE-2026-74959Critical· 9.1⚖ disputed
1mo ago

Mitigation bypass in the Storage: Cache API component

Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.34%via NVD
CVE-2026-74957High· 8.1⚖ disputed
1mo ago

Mitigation bypass in the Safe Browsing component

Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.30%via NVD
CVE-2026-58239Low· 3.7
1mo ago

SAP Approuter does not sufficiently validate tenant context in inbound requests

SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful ex…

Sunlitsap · approuterEPSS 0.22%via NVD
CVE-2026-18705Medium· 6.5
1mo ago

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficie…

Sunlitmongodb · mongodbEPSS 0.26%via NVD
CVE-2026-19579Medium· 5.4
1mo ago

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments …

Sunlitsnipeitapp · snipe-itEPSS 0.28%via NVD
CVE-2026-64827Critical· 9.8PoC
1mo ago

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current…

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current…

AbyssalTelenia Software · TVoxEPSS 0.48%via NVD
CVE-2026-48061Medium· 5.9
1mo ago

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whiteli…

Sunlitlitestar · litestarEPSS 0.34%via NVD
CVE-2026-56746High· 7.5
2mo ago

io.netty/netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746)

A flaw was found in Netty, a network application framework. A remote attacker can bypass security controls in the `CorsHandler` component by sending a specially crafted request with a null origin header. This bypasses the intended access r…

TwilightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.38%via CSAF
CVE-2026-16221High· 7.5
2mo ago

fast-uri: Fast-uri: Security policy bypass due to URL parsing inconsistency (CVE-2026-16221)

A flaw was found in fast-uri. This vulnerability arises because fast-uri does not correctly interpret backslash characters as authority delimiters in Uniform Resource Locators (URLs), unlike Node.js's native WHATWG URL parser. This discrep…

TwilightRed Hat · Red Hat Openshift Data Foundation 4.22EPSS 0.25%via CSAF
CWE-807 vulnerabilities (CVEs) · VulnSea