Threats Tagged 'cwe-1023'
View all threats tagged with 'cwe-1023'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1023'
Click on any threat for detailed analysis and mitigation recommendations
0 backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/views/crud/columns/color.blade.php inverts the escaped and raw rendering branches controlled by $column['escaped'], which defaults to true, causing $column['text'] to be rendered unescaped by default. An attacker who can store an unsanitized value in a color column can execute script in the browser of a user who views the CRUD list, including an administrator, with access to the victim's session-backed application capabilities. Exploitation requires write access to the stored color value and a victim viewing the list. This issue is fixed in versions 6.8.14 and 7.0.38. Join the discussion | CVE Database V5 | 09/14/2026, 17:55:45 UTC Added: 09/14/2026, 18:02:17 UTC |
0 Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. Join the discussion | CVE Database V5 | 09/08/2026, 17:13:57 UTC Added: 09/08/2026, 17:27:09 UTC |
0 Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing). Join the discussion | CVE Database V5 | 09/08/2026, 08:14:51 UTC Added: 09/02/2026, 16:22:57 UTC |
0 CVE-2026-54713 is a low-severity vulnerability in CakePHP Queue versions from 0.1.11 up to but not including 2.3.1. The issue arises because the QueueManager::getUniqueId() method generates job identifiers by sorting parameter values but drops associative-array keys, causing semantically different job parameters to produce identical identifiers. This can lead to legitimate jobs being incorrectly dropped as duplicates when the shouldBeUnique feature is enabled. The vulnerability is fixed in version 2.3.1. Join the discussion | CVE Database V5 | 08/27/2026, 17:03:31 UTC Added: 08/27/2026, 20:24:20 UTC |
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering. Join the discussion | CVE Database V5 | 08/04/2026, 17:23:47 UTC Added: 08/04/2026, 17:57:19 UTC |
0 On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild. Join the discussion | CVE Database V5 | 06/05/2026, 16:22:47 UTC Added: 06/05/2026, 16:48:54 UTC |
0 An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header values before comparison, which allows remote attackers to read cached responses via requests to URLs whose responses contain whitespace-padded Vary header values. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Navid Rezazadeh for reporting this issue. Join the discussion | CVE Database V5 | 06/03/2026, 15:30:43 UTC Added: 06/03/2026, 14:18:47 UTC |
0 CVE-2025-62000 is a high-severity vulnerability in BullWall Ransomware Containment versions 4.6.0.0 through 4.6.1.4 that affects a file inspection method relying on header bytes to detect encrypted files. An authenticated attacker can exploit this by encrypting files while preserving the first four bytes, thereby evading this specific detection method. Although other integrity-based detection mechanisms exist for common file extensions, this flaw represents a limitation in one detection approach rather than a full bypass. The vulnerability requires low privileges and no user interaction, impacting integrity and availability. Join the discussion | CVE Database V5 | 12/18/2025, 20:32:02 UTC Added: 12/18/2025, 20:41:29 UTC |
0 Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. Join the discussion | CVE Database V5 | 10/14/2025, 17:00:13 UTC Added: 10/14/2025, 17:16:52 UTC |
0 vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file vllm/multimodal/hasher.py, the MultiModalHasher class has a security and data integrity issue in its image hashing method. Currently, it serializes PIL.Image.Image objects using only obj.tobytes(), which returns only the raw pixel data, without including metadata such as the image’s shape (width, height, mode). As a result, two images of different sizes (e.g., 30x100 and 100x30) with the same pixel byte sequence could generate the same hash value. This may lead to hash collisions, incorrect cache hits, and even data leakage or security risks. This issue has been patched in version 0.9.0. Join the discussion | CVE Database V5 | 05/29/2025, 16:36:12 UTC Added: 05/29/2025, 16:59:45 UTC |
Showing 1 to 10 of 10 results