CWE-755

CWE-755 · 8 records · 6 with a public proof-of-concept

Records the NVD classes under CWE-755, highest CVSS first.

  1. HIGH 7.5CVE-2026-81516public PoC

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, ConsulDiscoveryClient constructs ConsulServiceInstance objects by parsing each registration's secure metadata w…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-81515public PoC

    Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, EurekaDiscoveryClient deserializes the registry response as one unit, and an unrecognized actionType or status,…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.5CVE-2026-101017

    A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results in handling of exceptional conditions. The attack can be exec…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.5CVE-2026-101016

    A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/aspf/rua/ruf leads to …

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.9CVE-2026-102274public PoC

    PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a JWK Set contains a malfo…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 4.3CVE-2026-101099public PoC

    A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. Performing a manipulation results in handling of exceptional conditions. The attack may be initi…

    AI risk analysis on Exploit-DB.ai →

  7. UNSCOREDCVE-2026-54580public PoC

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures to index-fetch callers. …

    AI risk analysis on Exploit-DB.ai →

  8. UNSCOREDCVE-2026-54578public PoC

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than a newly computed digest…

    AI risk analysis on Exploit-DB.ai →