VulnSea

CWE-843

CVEs classified under CWE-843, newest first.

139 CVEsRSS

CVE-2026-57975High· 7.5
2mo ago

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.61%via NVD
CVE-2026-58592High· 8.3PoC
2mo ago

Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader

Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp pa…

▾ MidnightLadybirdBrowser · LadybirdEPSS 0.55%via NVD
CVE-2026-55772High· 8.8
3mo ago

CedarJava has type confusion vulnerability

CedarJava has type confusion vulnerability

▾ Twilightcedarpolicy · com.cedarpolicy:cedar-javaEPSS 0.48%via GHSA
GHSA-f4xh-w4cj-qxq8High· 7.7
3mo ago

LangSmith SDK TracingMiddleware: Arbitrary server-side file read

LangSmith SDK TracingMiddleware: Arbitrary server-side file read

▾ Twilightlangsmith · langsmithvia GHSA
CVE-2026-12390High· 7.8
3mo ago

In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.

In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.

▾ Twilightazeotech · daqfactoryEPSS 0.18%via NVD
CVE-2026-12299Medium· 5.4
3mo ago

JIT miscompilation in the DOM: Core & HTML component

JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

▾ Sunlitmozilla · firefoxEPSS 0.31%via NVD
CVE-2026-12298Medium· 5.4
3mo ago

Memory safety bug fixed in Firefox 152

Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

▾ Sunlitmozilla · firefoxEPSS 0.31%via NVD
CVE-2026-44817High· 7.8
3mo ago

Microsoft Excel Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-45456High· 8.4
3mo ago

Microsoft Outlook and Word Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.45%via CVEORG
CVE-2026-45641High· 8.4
3mo ago

Windows Hyper-V Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.34%via CVEORG
CVE-2026-45600High· 7.8
3mo ago

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.33%via CVEORG
CVE-2026-45635High· 8.1
3mo ago

Windows UPnP Device Host Remote Code Execution Vulnerability

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.71%via CVEORG
CVE-2026-46306High· 7.5
3mo ago

In the Linux kernel, the following vulnerability has been resolved: flow_dissector: do not dissect PPPoE PFC frames RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT RECOMMENDED for PPPoE

In the Linux kernel, the following vulnerability has been resolved: flow_dissector: do not dissect PPPoE PFC frames RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT RECOMMENDED for PPPoE. In practice, pppd does no…

▾ Twilightlinux · linux_kernelEPSS 0.81%via NVD
CVE-2026-5946High· 7.5
4mo ago

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question sec…

▾ Twilightisc · bindEPSS 1.7%via NVD
CVE-2026-28983High· 7.5
4mo ago

A type confusion issue was addressed with improved checks

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5…

▾ Twilightapple · ipadosEPSS 0.80%via NVD
CVE-2026-6210None
4mo ago

A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* wi…

A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* wi…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-43038Critical· 9.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet…

In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() Sashiko AI-review observed: In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet…

▾ Midnightlinux · linux_kernelEPSS 0.44%via NVD
CVE-2026-43037Critical· 9.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the I…

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the I…

▾ MidnightEPSS 0.83%via NVD
CVE-2026-6732Medium· 6.5
5mo ago

A flaw was found in libxml2

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal entity reference. An attacker could exploit this by providing …

▾ Sunlitxmlsoft · libxml2EPSS 0.94%via NVD
CVE-2026-26162High· 7.8
5mo ago

Windows OLE Elevation of Privilege Vulnerability

Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-20806Medium· 5.5
5mo ago

Windows COM Server Information Disclosure Vulnerability

Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.34%via CVEORG
CVE-2026-27298High· 7.8
5mo ago

Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of…

▾ Twilightadobe · framemakerEPSS 0.29%via NVD
CVE-2026-40683High· 7.7
5mo ago

OpenStack Keystone: OpenStack Keystone: Unauthorized access due to incorrect LDAP user status handling (CVE-2026-40683)

A flaw was found in OpenStack Keystone. When using the LDAP identity backend, the system incorrectly processes the user enabled attribute if the user_enabled_invert configuration option is set to False. This error causes users marked as di…

▾ TwilightRed Hat · Red Hat OpenStack Platform 13 (Queens)EPSS 0.37%via CSAF
CVE-2026-39956Medium· 6.1
5mo ago

jq is a command-line JSON processor

jq is a command-line JSON processor. Prior to version 1.8.2, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relie…

▾ Sunlitjqlang · jqEPSS 0.17%via NVD
CVE-2026-27144High· 7.1
5mo ago

The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corrup…

The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct determination about non-overlapping moves, potentially leading to memory corrup…

▾ Twilightgolang · goEPSS 0.18%via NVD
CVE-2026-5914High· 8.8
5mo ago

Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension

Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.26%via NVD
CVE-2026-5871High· 8.8
5mo ago

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.45%via NVD
CVE-2026-5865High· 8.8PoC
5mo ago

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.45%via NVD
CVE-2026-34595Medium· 4.3
6mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields cl…

▾ Sunlitparseplatform · parse-serverEPSS 0.43%via NVD
CVE-2026-21710High· 7.5PoC
6mo ago

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `O…

A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `O…

▾ Midnightnodejs · node.jsEPSS 25%via NVD
CWE-843 vulnerabilities (CVEs) — page 4 · VulnSea