CVEs classified under CWE-436, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2023-24813 — CVSS 10.0 (critical): Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-lib, an attacker can…
CVE-2026-47767 — CVSS 9.8 (critical): Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12…
CVE-2026-8034 — CVSS 9.8 (critical): A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker…
CVE-2021-45327 — CVSS 9.8 (critical): Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API…
CVE-2020-10180 — CVSS 9.8 (critical): The ESET AV parsing engine allows virus-detection bypass via a crafted BZ2 Checksum field in an archive. This affects versions before 1294…
CVE-2019-19589 — CVSS 9.8 (critical): The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives…
CVE-2026-57580: authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default…
CVE-2026-14198 — CVSS 9.1 (critical): @fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching middleware paths…
CVE-2026-41248 — CVSS 9.1 (critical): Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and…
CVE-2026-6270 — CVSS 9.1 (critical): @fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instances. When a Fastify…
CVE-2026-33808 — CVSS 9.1 (critical): Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify router…
CVE-2026-33807 — CVSS 9.1 (critical): @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths to be doubled when…
CVE-2024-38428 — CVSS 9.1 (critical): url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in…
CVE-2019-18792 — CVSS 9.1 (critical): An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake…
CVE-2026-73615 — CVSS 8.8 (high): Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw command strings with…
CVE-2026-73614 — CVSS 8.8 (high): Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code…
CVE-2026-49473 — CVSS 8.8 (high): @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express…
CVE-2023-39481 — CVSS 8.8 (high): Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability. This vulnerability allows remote attackers…
CVE-2018-19966 — CVSS 8.8 (high): An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain…
CVE-2018-6560 — CVSS 8.8 (high): In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used…
CVE-2026-67201 — CVSS 8.6 (high): V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to…
CVE-2025-12816 — CVSS 8.6 (high): An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft…
CVE-2021-1587 — CVSS 8.6 (high): A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow…
CVE-2026-49332 — CVSS 8.5 (high): A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User)…
CVE-2023-36456 — CVSS 8.3 (high): authentik is an open-source Identity Provider. Prior to versions 2023.4.3 and 2023.5.5, authentik does not verify the source of the…
CVE-2020-9363 — CVSS 7.8 (high): The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection…
CVE-2020-9362 — CVSS 7.8 (high): The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total…
CVE-2026-44974: @hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrence of each duplicate…
CVE-2021-34699 — CVSS 7.7 (high): A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an…
CVE-2020-3200 — CVSS 7.7 (high): A vulnerability in the Secure Shell (SSH) server code of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote…
CVE-2026-68968 — CVSS 7.5 (high): Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed…
CVE-2026-18446 — CVSS 7.5 (high): fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a…
CVE-2026-16221 — CVSS 7.5 (high): Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal…
CVE-2026-13676 — CVSS 7.5 (high): fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path…
CVE-2026-42551 — CVSS 7.5 (high): Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP-Method-Override…
CVE-2026-6322 — CVSS 7.5 (high): fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters…
CVE-2026-27444 — CVSS 7.5 (high): SEPPmail Secure Email Gateway before version 15.0.1 incorrectly interprets email addresses in the email headers, causing an interpretation…
CVE-2026-0958 — CVSS 7.5 (high): GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4…
CVE-2026-25223 — CVSS 7.5 (high): Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability exists in Fastify…
CVE-2024-55629 — CVSS 7.5 (high): Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, TCP…
CVE-2023-52892 — CVSS 7.5 (high): In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS…
CVE-2024-34478 — CVSS 7.5 (high): btcd before 0.24.0 does not correctly implement the consensus rules outlined in BIP 68 and BIP 112, making it susceptible to consensus…
CVE-2023-40718 — CVSS 7.5 (high): A interpretation conflict in Fortinet IPS Engine versions 7.321, 7.166 and 6.158 allows attacker to evade IPS features via crafted TCP…
CVE-2022-48473 — CVSS 7.5 (high): There is a misinterpretation of input vulnerability in Huawei Printer. Successful exploitation of this vulnerability may cause the printer…
CVE-2022-48471 — CVSS 7.5 (high): There is a misinterpretation of input vulnerability in Huawei Printer. Successful exploitation of this vulnerability may cause the printer…
CVE-2022-48261 — CVSS 7.5 (high): There is a misinterpretation of input vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation of this vulnerability may cause…
CVE-2022-48230 — CVSS 7.5 (high): There is a misinterpretation of input vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could lead to DoS.
CVE-2022-48279 — CVSS 7.5 (high): In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application…