CWE-841
CVEs classified under CWE-841, newest first.
14 CVEsRSS
CVE-2026-48974Medium· 5.4HomeBox: Forced Group Membership Without Consent in Homebox AddMember Handler
HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, ta…
CVE-2026-80998Medium· 5.5kernel: net: bnxt: ring the doorbell when SW USO exits early (CVE-2026-80998)
A flaw was found in the Linux kernel's `bnxt` network driver. When processing a burst of packets, the driver may fail to notify the network device (ring the doorbell) if the Software UDP Segmentation Offload (SW USO) path exits prematurely…
CVE-2026-78135Medium· 5.6libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
CVE-2026-87503Medium· 6.5Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page
Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security seve…
CVE-2026-53637Medium· 6.5Sylius is an Open Source eCommerce Framework on Symfony
Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is co…
CVE-2026-67279Medium· 6.9PoCRouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the…
CVE-2026-82423Medium· 5.4A vulnerability has been found in macrozheng mall up to 1.0.3
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcem…
CVE-2026-55763HighKlever-Go is the Go implementation of the Klever blockchain protocol
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the royaltiesToPay <= 0 early…
CVE-2026-77508Low· 3.5Weblate is a web based localization tool
Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invi…
CVE-2026-16103Medium· 4.3A flaw was found in the keycloak-services component of Keycloak
A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handl…
CVE-2026-48505High· 7.4Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission
Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission
CVE-2026-42246High· 7.4Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without s…
CVE-2026-30783Critical· 9.8A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated …
A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated …
CVE-2024-50063High· 7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tail call between progs attached to different hooks bpf progs can be attached to kernel functions, and the attached functions can take different parameter…
In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tail call between progs attached to different hooks bpf progs can be attached to kernel functions, and the attached functions can take different parameter…