CWE-923
CWE-923 · 4 records · 2 with a public proof-of-concept
Records the NVD classes under CWE-923, highest CVSS first.
- HIGH 8.2CVE-2026-96454public PoC
Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together they hand native functionality to untrusted web content. The first is in src-tauri/capabilities/def…
- MEDIUM 5.7CVE-2026-91166public PoC
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead passes ssh_options.host an…
- UNSCOREDCVE-2026-101891
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session.
- UNSCOREDCVE-2026-82932
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every servic…