CVEs classified under CWE-1023, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (11)
CVE-2026-4599 — CVSS 9.1 (critical): Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the…
CVE-2026-24255 — CVSS 7.5 (high): NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by…
CVE-2025-62000 — CVSS 7.1 (high): BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection method that…
CVE-2026-91768 — CVSS 6.5 (medium): The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients…
CVE-2026-53839 — CVSS 6.5 (medium): OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes…
CVE-2025-55333 — CVSS 6.1 (medium): Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a…
CVE-2025-46722 — CVSS 4.2 (medium): vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file…
CVE-2026-54713 — CVSS 3.7 (low): CakePHP Queue is a queue-interop compatible queueing library. From 0.1.11 until 2.3.1, QueueManager::getUniqueId() generates identifiers…
CVE-2026-48587 — CVSS 3.1 (low): An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip…
CVE-2026-91836 — CVSS 2.8 (low): A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of…