VulnSea

CWE-807

CVEs classified under CWE-807, newest first.

43 CVEsRSS

CVE-2026-16093Medium· 5.4
2mo ago

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker wit…

Sunlitredhat · build_of_keycloakEPSS 0.39%via NVD
GHSA-cqwv-9qjx-vxw2Medium· 5.3
2mo ago

OpenClaw: Skill Workshop apply flow could override pending approval

OpenClaw: Skill Workshop apply flow could override pending approval

Sunlitopenclaw · openclawvia GHSA
CVE-2026-53492High· 8.2
2mo ago

github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint r…

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotat…

TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.35%via CSAF
GHSA-x845-2f78-7v36High· 8.6
3mo ago

Blocky DNSSEC validation bypass and validation-cache scope pollution

Blocky DNSSEC validation bypass and validation-cache scope pollution

Twilight0xERR0R · github.com/0xERR0R/blockyvia GHSA
GHSA-8hj2-w4c9-fjfqLow· 4.2
3mo ago

Duplicate Advisory: BlueBubbles sender policy could match mutable conversation identifiers

Duplicate Advisory: BlueBubbles sender policy could match mutable conversation identifiers

Sunlitopenclaw · openclawvia GHSA
GHSA-j9gf-vw2f-9hrwHigh· 8.1
3mo ago

Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation

Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation

Twilightappsmith · com.appsmith:servervia GHSA
CVE-2026-44649Critical· 9.8
3mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Auth…

MidnightEPSS 0.22%via NVD
CVE-2026-8328Medium· 5.3
4mo ago

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse…

SunlitRed Hat · Red Hat Hardened ImagesEPSS 0.46%via NVD
CVE-2026-34486High· 7.5CISA KEVPoC
5mo ago

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …

Abyssalapache · tomcatEPSS 99%via NVD
CVE-2026-34040High· 8.4PoC
5mo ago

Moby: Moby: Authorization bypass vulnerability (CVE-2026-34040)

A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container enviro…

MidnightRed Hat · Multicluster Global Hub 1.4.9EPSS 9.1%via CSAF
CVE-2026-21509High· 7.8CISA KEV0dayPoC
7mo ago

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Abyssalmicrosoft · 365_appsEPSS 73%via NVD
CVE-2026-20849High· 7.5
8mo ago

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · windows_10_1607EPSS 1.0%via NVD
CVE-2024-11146Medium· 6.3
1y ago

TrueFiling authorization bypass via user-controlled keys

TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect public legal documentation into cases. TrueFiling is an entirely cloud-hosted application.…

Sunliti3 Verticals · TrueFilingEPSS 0.33%via CVEORG
CWE-807 vulnerabilities (CVEs) — page 2 · VulnSea