CWE-754

CWE-754 · 5 records · 4 with a public proof-of-concept

Records the NVD classes under CWE-754, highest CVSS first.

  1. HIGH 8.3CVE-2026-91733

    Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

    chrome

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.3CVE-2026-73549public PoC

    Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address paths reconstruct scoped IPv6 addresses through addressAsSt…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.3CVE-2026-94105public PoC

    NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to disable password recovery by supplying an invalid code parameter. Attackers can send a GET request w…

    AI risk analysis on Exploit-DB.ai →

  4. LOW 3.3CVE-2026-18852public PoC

    A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. Such manipulation leads to…

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-77411public PoC

    RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared AMQP longstr length exceeds 0x7FFFFFFF instead of returning ErrSyntax. The function leaves the declared field bytes u…

    AI risk analysis on Exploit-DB.ai →