CWE-807
CVEs classified under CWE-807, newest first.
43 CVEsRSS
CVE-2026-16093Medium· 5.4Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker wit…
GHSA-cqwv-9qjx-vxw2Medium· 5.3OpenClaw: Skill Workshop apply flow could override pending approval
OpenClaw: Skill Workshop apply flow could override pending approval
CVE-2026-53492High· 8.2github.com/containerd/containerd: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint r…
A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) implementation, which allows Kubernetes to interact with container runtimes, improperly trusts Container Device Interface (CDI) annotat…
GHSA-x845-2f78-7v36High· 8.6Blocky DNSSEC validation bypass and validation-cache scope pollution
Blocky DNSSEC validation bypass and validation-cache scope pollution
GHSA-8hj2-w4c9-fjfqLow· 4.2Duplicate Advisory: BlueBubbles sender policy could match mutable conversation identifiers
Duplicate Advisory: BlueBubbles sender policy could match mutable conversation identifiers
GHSA-j9gf-vw2f-9hrwHigh· 8.1Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
CVE-2026-44649Critical· 9.8SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Auth…
CVE-2026-8328Medium· 5.3The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse…
CVE-2026-34486High· 7.5CISA KEVPoCMissing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to …
CVE-2026-34040High· 8.4PoCMoby: Moby: Authorization bypass vulnerability (CVE-2026-34040)
A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container enviro…
CVE-2026-21509High· 7.8CISA KEV0dayPoCReliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-20849High· 7.5Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
CVE-2024-11146Medium· 6.3TrueFiling authorization bypass via user-controlled keys
TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect public legal documentation into cases. TrueFiling is an entirely cloud-hosted application.…