CVEs classified under CWE-180, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (30)
CVE-2026-15704 — CVSS 9.8 (critical): In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass…
CVE-2026-24895 — CVSS 9.8 (critical): FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode…
CVE-2026-73420: NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer…
CVE-2026-82481: The cohttp package before 6.3.0 for OCaml allows directory traversal.
CVE-2026-52747 — CVSS 8.6 (high): ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the…
CVE-2026-48721 — CVSS 8.6 (high): Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command…
CVE-2026-45022 — CVSS 7.5 (high): go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git…
CVE-2026-39364 — CVSS 7.5 (high): Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be…
CVE-2026-69246 — CVSS 7.2 (high): Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host…
CVE-2026-105050: PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation…
CVE-2026-42462 — CVSS 7.0 (high): Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18…
CVE-2026-95811 — CVSS 6.5 (medium): Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an…
CVE-2026-69245 — CVSS 6.5 (medium): Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain…
CVE-2026-93326: A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make…
CVE-2026-72917 — CVSS 5.9 (medium): AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to…
CVE-2025-43716 — CVSS 5.8 (medium): A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to the URI of the…
CVE-2025-33194 — CVSS 5.7 (medium): NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A…
CVE-2026-100547 — CVSS 5.5 (medium): OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid…
CVE-2026-34475 — CVSS 5.4 (medium): Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of /…
CVE-2026-100230 — CVSS 5.3 (medium): Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the /…
CVE-2026-7120 — CVSS 5.3 (medium): @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for…
CVE-2026-39409 — CVSS 5.3 (medium): Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not…
CVE-2026-34786 — CVSS 5.3 (medium): Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules evaluates several…
CVE-2026-76203: Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows…
CVE-2026-102269 — CVSS 4.8 (medium): PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature…
CVE-2026-100674 — CVSS 4.3 (medium): stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames with forbidden…
CVE-2026-97764 — CVSS 3.7 (low): django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an…
CVE-2026-79300 — CVSS 3.5 (low): SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can…
CVE-2024-28607 — CVSS 2.9 (low): The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as…
CVE-2026-82736: Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string…