CVEs classified under CWE-807, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-84474 — CVSS 9.9 (critical): A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is…
CVE-2026-64827 — CVSS 9.8 (critical): Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability…
CVE-2025-13926 — CVSS 9.8 (critical): An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary…
CVE-2026-32975 — CVSS 9.8 (critical): OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names…
CVE-2025-12488 — CVSS 9.8 (critical): oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability…
CVE-2025-12487 — CVSS 9.8 (critical): oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability…
CVE-2025-49827 — CVSS 9.8 (critical): Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22.0 and Secrets…
CVE-2026-82533 — CVSS 9.6 (critical): DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP…
CVE-2025-1126 — CVSS 9.3 (critical): A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.
CVE-2026-66768 — CVSS 9.0 (critical): SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A…
CVE-2024-29039 — CVSS 9.0 (critical): tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to manipulate…
CVE-2026-63041 — CVSS 8.8 (high): Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate…
CVE-2026-33068 — CVSS 8.8 (high): Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the…
CVE-2024-55354 — CVSS 8.8 (high): Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism…
CVE-2021-31999 — CVSS 8.8 (high): A Reliance on Untrusted Inputs in a Security Decision vulnerability in Rancher allows users in the cluster to act as others users in the…
CVE-2026-9077 — CVSS 8.5 (high): IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write…
CVE-2026-87479 — CVSS 8.3 (high): Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the…
CVE-2026-81179 — CVSS 8.1 (high): SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while…
CVE-2026-13059 — CVSS 8.1 (high): An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level…
CVE-2024-13974 — CVSS 8.1 (high): A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers…
CVE-2021-36777 — CVSS 8.1 (high): A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to…
CVE-2023-0009 — CVSS 7.8 (high): A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute…
CVE-2026-25958 — CVSS 7.7 (high): Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a…
CVE-2026-29134 — CVSS 7.5 (high): SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain…
CVE-2026-20849 — CVSS 7.5 (high): Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
CVE-2025-59152 — CVSS 7.5 (high): Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely bypassed by…
CVE-2024-51561 — CVSS 7.5 (high): This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated…
CVE-2026-56681 — CVSS 7.3 (high): 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing…
CVE-2026-41390 — CVSS 7.3 (high): OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap /usr/bin/script…
CVE-2026-41380 — CVSS 7.3 (high): OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence…
CVE-2026-102117 — CVSS 7.2 (high): On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the…
CVE-2026-87858: Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated…
CVE-2026-41299 — CVSS 7.1 (high): OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only provenance fields…
CVE-2026-32057 — CVSS 7.1 (high): OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pairing mechanism that…
CVE-2025-0117: A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a locally…
CVE-2025-53717 — CVSS 7.0 (high): Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to…
CVE-2021-29479 — CVSS 7.0 (high): Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a user supplied `X-Forwarded-Host` header can be used to…
CVE-2026-79701: Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP…
CVE-2026-79700: Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro…
CVE-2026-0390 — CVSS 6.7 (medium): Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature…
CVE-2026-53789 — CVSS 6.5 (medium): rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete…
CVE-2026-18705 — CVSS 6.5 (medium): An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve…
CVE-2026-23848 — CVSS 6.5 (medium): MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypass via…
CVE-2025-65328 — CVSS 6.5 (medium): Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client IP without…
CVE-2022-20744 — CVSS 6.5 (medium): A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote…
CVE-2026-39807: Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on…
CVE-2024-47254 — CVSS 6.3 (medium): In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker…