CWE-180

CWE-180 · 6 records · 4 with a public proof-of-concept

Records the NVD classes under CWE-180, highest CVSS first.

  1. MEDIUM 6.5CVE-2026-95811

    Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost's locationRules regula…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.5CVE-2026-100547public PoC

    OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), alternate but valid `file:` URL spellings supplied over the Agent Client Protocol (ACP) were treated as relative paths and were incorrectly …

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.3CVE-2026-100230public PoC

    Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is written to a startup directo…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 4.8CVE-2026-102269public PoC

    PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL characters a…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 4.3CVE-2026-100674public PoC

    stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames with forbidden characters by submitting Unicode letters that transform into rejected characters. Attackers can bypass character allowlists …

    AI risk analysis on Exploit-DB.ai →

  6. LOW 3.7CVE-2026-97764

    django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.

    AI risk analysis on Exploit-DB.ai →