VulnSea

CWE-843

CVEs classified under CWE-843, newest first.

139 CVEsRSS

CVE-2026-77889High· 7.5
2w ago

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.2%via NVD
CVE-2026-77888High· 7.5
2w ago

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.2%via NVD
CVE-2026-77499High· 7.5
2w ago

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.2%via NVD
CVE-2026-77494High· 7.5
2w ago

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.2%via NVD
CVE-2026-72938Medium· 6.5
2w ago

Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · 365_appsEPSS 0.92%via NVD
CVE-2026-70584High· 7.8
2w ago

Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-69717High· 8.0
2w ago

Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.

Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.77%via NVD
CVE-2026-69679Medium· 5.7
2w ago

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.65%via NVD
CVE-2026-69637Medium· 5.7
2w ago

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.65%via NVD
CVE-2026-69324High· 7.8
2w ago

Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.

Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-69308Medium· 5.5
2w ago

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

Out-of-bounds read in Microsoft Standard XPS allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.41%via NVD
CVE-2026-82057Medium· 6.5
2w ago

A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod server process

A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod server process. By specifying a custom WiredTiger storage configuration option with an incompatible value during coll…

▾ Sunlitmongodb · mongodbEPSS 0.42%via NVD
CVE-2026-20508Medium· 6.7
2w ago

In Power HAL, there is a possible escalation of privilege due to type confusion

In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploita…

▾ SunlitMediaTek, Inc. · MediaTek chipsetEPSS 0.11%via NVD
CVE-2026-85051High· 8.8
3w ago

Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.45%via NVD
CVE-2026-85046High· 8.8CISA KEV0dayPoC
3w ago

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 49%via NVD
CVE-2026-53600Medium
3w ago

async-tar is a tar archive reading/writing library for async Rust

async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g header) …

▾ Sunlitasync-tar · async-tarEPSS 0.45%via NVD
CVE-2026-72984High· 8.8
1mo ago

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · edge_chromiumEPSS 0.82%via NVD
CVE-2026-19315None
1mo ago

A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.

▾ SunlitEPSS 0.46%via NVD
CVE-2026-80183High· 7.1
1mo ago

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/…

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/…

▾ TwilightOpenStack · KeystoneEPSS 0.38%via NVD
CVE-2026-59304Low· 3.1
1mo ago

Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

▾ SunlitEPSS 0.21%via NVD
CVE-2026-79769Medium· 5.5
1mo ago

Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode without …

Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode without …

▾ SunlitEPSS 0.31%via NVD
CVE-2026-72844Medium· 6.3PoC
1mo ago

The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment::add_inductive in src/kernel/inductive.cpp did not type check the nested inductive appli…

The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment::add_inductive in src/kernel/inductive.cpp did not type check the nested inductive appli…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-59940Critical· 9.8
1mo ago

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general…

▾ Midnightseroval · serovalEPSS 0.81%via NVD
CVE-2026-52829High· 7.5
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node using the default Linux dual-stack listener configuration. The handshake path canonicalized …

▾ Twilightzebra-network · zebra-networkEPSS 0.61%via NVD
CVE-2026-16239High· 8.8
1mo ago

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreS…

▾ Twilightpostgresql · postgresqlEPSS 0.68%via NVD
CVE-2026-16238High· 8.8
1mo ago

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, mino…

▾ Twilightpostgresql · postgresqlEPSS 0.41%via NVD
CVE-2026-14680High· 8.8
1mo ago

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a clas…

▾ Twilightpostgresql · postgresqlEPSS 0.42%via NVD
CVE-2026-14671High· 8.8
1mo ago

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repo…

▾ Twilightpostgresql · postgresqlEPSS 0.42%via NVD
CVE-2026-14668High· 8.1
1mo ago

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calcul…

▾ Twilightpostgresql · postgresqlEPSS 0.33%via NVD
CVE-2026-70339Medium· 5.4
1mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.41%via CVEORG
CWE-843 vulnerabilities (CVEs) — page 2 · VulnSea