CWE-706

CWE-706 · 5 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-706, highest CVSS first.

  1. CRITICAL 9.9CVE-2026-92951public PoC

    vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding pac…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-85491

    Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone. Catalyst::Seal replaces the dispatcher's prepare_action with a version that …

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.1CVE-2026-91727

    Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Hig…

    chrome · macos

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.8CVE-2026-77605public PoC

    Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command script whose name is th…

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-87720

    Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction logic (ProjectCacheImpl) in Gerrit Code Review versions 2.16.0 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an aut…

    AI risk analysis on Exploit-DB.ai →