VulnSea

CWE-841

CVEs classified under CWE-841, newest first.

14 CVEsRSS

CVE-2026-48974Medium· 5.4
today

HomeBox: Forced Group Membership Without Consent in Homebox AddMember Handler

HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, ta…

Sunlitsysadminsmedia · homeboxvia CVEORG
CVE-2026-80998Medium· 5.5
1w ago

kernel: net: bnxt: ring the doorbell when SW USO exits early (CVE-2026-80998)

A flaw was found in the Linux kernel's `bnxt` network driver. When processing a burst of packets, the driver may fail to notify the network device (ring the doorbell) if the Software UDP Segmentation Offload (SW USO) path exits prematurely…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.47%via CSAF
CVE-2026-78135Medium· 5.6
1w ago

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

Sunlitstrongswan · strongswanEPSS 0.36%via NVD
CVE-2026-87503Medium· 6.5
1w ago

Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security seve…

Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-53637Medium· 6.5
1w ago

Sylius is an Open Source eCommerce Framework on Symfony

Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is co…

SunlitSylius · SyliusEPSS 0.29%via NVD
CVE-2026-67279Medium· 6.9PoC
2w ago

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the…

TwilightMikrotik · RouterOSEPSS 0.45%via NVD
CVE-2026-82423Medium· 5.4
3w ago

A vulnerability has been found in macrozheng mall up to 1.0.3

A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcem…

SunlitEPSS 0.25%via NVD
CVE-2026-55763High
3w ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the royaltiesToPay <= 0 early…

Twilightklever-io · github.com/klever-io/klever-goEPSS 0.30%via NVD
CVE-2026-77508Low· 3.5
3w ago

Weblate is a web based localization tool

Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invi…

SunlitEPSS 0.15%via NVD
CVE-2026-16103Medium· 4.3
2mo ago

A flaw was found in the keycloak-services component of Keycloak

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-Initiated Backchannel Authentication (CIBA) initiation handl…

Sunlitredhat · build_of_keycloakEPSS 0.34%via NVD
CVE-2026-48505High· 7.4
2mo ago

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission

Twilightfilament · filament/filamentEPSS 0.30%via GHSA
CVE-2026-42246High· 7.4
4mo ago

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without s…

Twilightruby-lang · net::imapEPSS 0.31%via NVD
CVE-2026-30783Critical· 9.8
6mo ago

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated …

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated …

MidnightEPSS 0.38%via NVD
CVE-2024-50063High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tail call between progs attached to different hooks bpf progs can be attached to kernel functions, and the attached functions can take different parameter…

In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tail call between progs attached to different hooks bpf progs can be attached to kernel functions, and the attached functions can take different parameter…

Twilightdebian · debian_linuxEPSS 0.23%via NVD
CWE-841 vulnerabilities (CVEs) · VulnSea