CWE-697

CWE-697 · 7 records · 7 with a public proof-of-concept

Records the NVD classes under CWE-697, highest CVSS first.

  1. CRITICAL 9.1CVE-2026-92395public PoC

    @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6 notation with an IPv…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.1CVE-2026-92087public PoC

    @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the relation "or" option together with the run "all" option and o…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.5CVE-2026-79913public PoC

    Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP without decoding NAT64, IPv4-compatible, and 6to4 IPv4-in-IPv6…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 4.8CVE-2026-85292public PoC

    InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the required role by using PHP's loose inequality operator. Under a non…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 4.3CVE-2026-93957public PoC

    A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleFilter of the file src/SearchEngine.php of the component Filter Matching. The manipulation leads to incorrect comparison. Remote exploitation…

    AI risk analysis on Exploit-DB.ai →

  6. UNSCOREDCVE-2026-101913public PoC

    ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only fe80::/64 instead of the complete fe80::/10 IPv6 link-local range. An attacker-controlle…

    AI risk analysis on Exploit-DB.ai →

  7. UNSCOREDCVE-2026-101912public PoC

    ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare masked binary strings without validating that both operands use the same IP family. …

    AI risk analysis on Exploit-DB.ai →