CWE-440

CWE-440 · 3 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-440, highest CVSS first.

  1. HIGH 8.8CVE-2026-93675

    IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.

    AI risk analysis on Exploit-DB.ai →

  2. LOW 3.7CVE-2026-35191public PoC

    Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-97687public PoC

    urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail to remain …

    AI risk analysis on Exploit-DB.ai →