VulnSea

CWE-843

CVEs classified under CWE-843, newest first.

139 CVEsRSS

CVE-2026-65807High· 8.8
1mo ago

Microsoft Excel Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.82%via CVEORG
CVE-2026-68811High· 7.8
1mo ago

Microsoft Excel Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-64904High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-68803High· 7.8
1mo ago

Microsoft Excel Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-18701Medium· 6.5
1mo ago

An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter

An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter. This could result in a denial of ser…

▾ Sunlitmongodb · mongodbEPSS 0.40%via NVD
CVE-2026-61932High· 7.8
1mo ago

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-14644High· 7.2
1mo ago

Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API

Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administ…

▾ Twilightsonatype · nexus_repository_managerEPSS 0.34%via NVD
CVE-2026-54164Medium· 6.5
1mo ago

API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)

API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)

▾ Sunlitapi-platform · api-platform/coreEPSS 0.34%via GHSA
CVE-2026-66321High· 7.4
1mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 1.1%via CVEORG
CVE-2026-55771High· 8.8
2mo ago

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

▾ Twilightcedarpolicy · com.cedarpolicy:cedar-javaEPSS 0.57%via GHSA
CVE-2026-47219High· 7.5
2mo ago

find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server (CVE-2026-47219)

A flaw was found in find-my-way, a routing module for Node.js. A remote attacker could exploit this vulnerability when find-my-way is used with Node's HTTP/2 server. By sending specially crafted HTTP/2 method values, an attacker can cause …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.46%via CSAF
GHSA-2x35-3fw4-9jr4High
2mo ago

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

▾ Twilightn8n · n8nvia GHSA
CVE-2026-50381Medium· 5.5
2mo ago

Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability

Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.40%via CVEORG
CVE-2026-50390High· 7.0
2mo ago

Windows Kernel Elevation of Privilege Vulnerability

Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.28%via CVEORG
CVE-2026-50421High· 7.8
2mo ago

Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-50491High· 7.0
2mo ago

Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability

Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.28%via CVEORG
CVE-2026-55024High· 7.8
2mo ago

Microsoft Excel Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-50686High· 8.1
2mo ago

Windows OLE Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.71%via CVEORG
CVE-2026-55025High· 7.8
2mo ago

Microsoft Excel Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-55022High· 7.8
2mo ago

Microsoft Office Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-54116Medium· 6.5
2mo ago

Microsoft SQL Server Information Disclosure Vulnerability

Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft SQL Server 2025 (CU 6)EPSS 1.00%via CVEORG
CVE-2026-58541High· 7.8
2mo ago

Microsoft DWM Core Library Elevation of Privilege Vulnerability

Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-57108High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.2%via CVEORG
CVE-2026-59205High· 7.5
2mo ago

Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API (CVE-2026-59205)

A flaw was found in Pillow, a Python imaging library. This vulnerability allows an attacker to trigger controlled native heap corruption by supplying an output image whose mode does not match the transform's declared output mode when using…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.66%via CSAF
CVE-2026-59871Medium· 5.3
2mo ago

node-tar: node-tar: Denial of Service due to incorrect PAX path handling (CVE-2026-59871)

A flaw was found in node-tar, a library for manipulating tar archives in Node.js. This vulnerability occurs when the library incorrectly converts specific archive path values into numbers, leading to an error during subsequent path process…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.64%via CSAF
CVE-2026-58290High· 7.5
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.43%via CVEORG
CVE-2026-58289Critical· 9.0PoC
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ AbyssalMicrosoft · Microsoft Edge (Chromium-based)EPSS 2.0%via CVEORG
CVE-2026-58285High· 8.3
2mo ago

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.61%via CVEORG
CVE-2026-58283High· 8.1
2mo ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.44%via CVEORG
CVE-2026-58295High· 8.3
2mo ago

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.51%via CVEORG
CWE-843 vulnerabilities (CVEs) — page 3 · VulnSea