Falhas do tipo CWE-706

58 resultados
CVE-2026-33732MEDIUMsrvx is vulnerable to middleware bypass via absolute URI in request lineEPSS 0.2%CVE-2026-35635MEDIUMOpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology ChatEPSS 0.2%CVE-2024-45305LOWgix-path uses local config across repos when it is the highest scopeEPSS 0.2%CVE-2026-33490LOWh3: Missing Path Segment Boundary Check in `mount()` Causes Middleware Execution on Unrelated Prefix-Matching RoutesEPSS 0.2%CVE-2026-45306MEDIUMpyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session DirectoryEPSS 0.2%CVE-2024-55058MEDIUMAn insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerabiliEPSS 0.2%CVE-2026-35039CRITICALfast-jwt Affected by Cache Confusion via cacheKeyBuilder Collisions Can Return Claims From a Different Token (Identity/Authorization Mixup)EPSS 0.2%CVE-2026-1230MEDIUMUse of Incorrectly-Resolved Name or Reference in GitLabEPSS 0.2%CVE-2025-65105MEDIUMApptainer ineffective application of selinux and apparmor --security optionsEPSS 0.2%CVE-2026-8716MEDIUMUse of Incorrectly-Resolved Name or Reference in GitLabEPSS 0.2%CVE-2026-54282LOWStarlette: Unvalidated request path concatenated into authority poisons request.url.hostnameEPSS 0.2%CVE-2026-35358MEDIUMuutils coreutils cp Semantic Loss and Potential Denial of Service with -R via Device Node Stream ReadingEPSS 0.2%CVE-2026-42254MEDIUMHickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query thatEPSS 0.2%CVE-2025-62378MEDIUMCommandKit exposes incorrect command name in context object for message command aliasesEPSS 0.1%CVE-2026-41131MEDIUMOpenFGA has Improper Policy EnforcementEPSS 0.1%CVE-2025-64750MEDIUMSingluarity ineffectively applies of selinux / apparmor LSM process labelsEPSS 0.1%CVE-2024-51746LOWUse of incorrect Rekor entries during verification in gitsignEPSS 0.1%CVE-2025-13437MEDIUMArbitrary node_modules Directory Deletion in Google zxEPSS 0.1%