CWE-799
CWE-799 · 3 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-799, highest CVSS first.
- MEDIUM 5.4CVE-2026-100603public PoC
ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordinary authenticated accounts can report a visible skill and trigger automatic hiding (moderationStatus: hidden) of that skill from the catalog …
- LOW 3.7CVE-2026-105237public PoC
A vulnerability was detected in linlinjava litemall up to 1.8.0. This affects an unknown part of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java of the component Login Endpoint. The manipulation results in i…
- UNSCOREDCVE-2026-84461public PoC
Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an attacker try unlimited password guesses for any account without triggering Zammad's normal lockout or rate limiting. The response also revealed…