CWE-807
High likelihoodReliance on Untrusted Inputs in a Security Decision
The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
76 vulnerabilities with CWE-807
CVE-2026-21509
HIGH
KEV
Microsoft 365 Apps and Office - Security Feature Bypass via Untrusted Input
CVSS 7.8
CVE-2026-23848
MEDIUM
MyTube < 1.7.71 - Unauthenticated Rate Limit Bypass via X-Forwarded-For Header Spoofing
CVSS 6.5
CVE-2026-20849
HIGH
Windows Kerberos - Privilege Escalation
CVSS 7.5
CVE-2025-13926
CRITICAL
Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision
CVSS 9.8
CVE-2025-65328
MEDIUM
mega-fence < 25.1.914 - IP Spoofing via X-Forwarded-For Header
CVSS 6.5
CVE-2025-66507
HIGH
1Panel < 2.0.14 - Unauthenticated CAPTCHA Bypass via Client-Controlled Parameter
CVSS 7.5
CVE-2025-66577
MEDIUM
cpp-httplib <0.27.0 - Log Poisoning
CVSS 5.3
CVE-2025-66570
CRITICAL
cpp-httplib <0.27.0 - Info Disclosure
CVSS 10.0
CVE-2025-10161
HIGH
Turkguven Software Technologies Inc. Perfektive <12574.2701 - Auth ...
CVSS 7.3
CVE-2025-12488
CRITICAL
oobabooga text-generation-webui - RCE
CVSS 9.8
CVE-2025-12487
CRITICAL
oobabooga text-generation-webui - RCE
CVSS 9.8
CVE-2025-11271
MEDIUM
Easy Digital Downloads <3.5.2 - Order Manipulation
CVSS 5.3
CVE-2025-53717
HIGH
Windows VBS Enclave - Privilege Escalation
CVSS 7.0
CVE-2025-59152
HIGH
Litestar 2.17.0 - Rate Limit Bypass via X-Forwarded-For Header Manipulation
CVSS 7.5
CVE-2025-55736
MEDIUM
flaskBlog <2.8.0 - Privilege Escalation
CVSS 6.5
CVE-2025-55735
MEDIUM
FlaskBlog < 2.8.0 - Stored Cross-Site Scripting via Post Content
CVSS 5.4
CVE-2025-53882
MEDIUM
openSUSE mailman3 logrotate - Arbitrary Process Signal
CVSS 4.4
CVE-2025-49827
CRITICAL
Conjur 1.19.5-1.22.0 and 13.1-13.5 - IAM Authenticator Bypass via Malformed Regular Expression
CVSS 9.8
CVE-2025-0117
HIGH
GlobalProtect <unknown - Privilege Escalation
CVE-2025-1969
MEDIUM
AWS TEAM for IAM Identity Center < 1.2.2 - Request Spoofing via Input Validation Bypass
CVSS 4.3
CVE-2025-1126
CRITICAL
Lexmark Print Management Client - RCE
CVSS 9.3
CVE-2025-24369
LOW
Anubis < v1.11.0-37 - Client-Specified Difficulty Bot Protection Bypass
CVE-2024-13974
HIGH
Sophos Firewall < 21.0.1 - Remote Code Execution via Up2Date DNS Control
CVSS 8.1
CVE-2024-55354
HIGH
Lucee <5.4.7.3 LTS & 6 <6.1.1.118 - Code Injection
CVSS 8.8
CVE-2024-52327
MEDIUM
ECOVACS Home < 3.0.2 - Authenticated PIN Bypass for Live Video Feed Access
CVSS 6.5
Details
Vulnerabilities
76
Exploit Likelihood
High