Threats Tagged 'cwe-138'
View all threats tagged with 'cwe-138'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-138'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-55841 is a vulnerability in Graylog2-server affecting the FortiGate key-value syslog parser. It mishandles field-like text inside quoted values, allowing crafted syslog messages to manipulate or remove security-log fields. This can enable an unauthenticated network sender to obscure malicious activity by evading logging. The issue is fixed in Graylog Server versions 6.3.12, 7.0.7, 7.1.2, and Graylog Forwarder version 7.3. Join the discussion | CVE Database V5 | 08/28/2026, 22:11:08 UTC Added: 08/28/2026, 22:22:46 UTC |
0 Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 05/07/2026, 20:58:24 UTC Added: 05/07/2026, 21:22:35 UTC |
0 Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. Join the discussion | CVE Database V5 | 04/14/2026, 16:57:31 UTC Added: 04/14/2026, 17:32:34 UTC |
0 tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual <script> element. If an attacker injected an HTML element, it could clobber the document.currentScript property. This causes the script to resolve incorrectly to an element instead of the <script> tag, leading to unexpected behavior or failure to load the script path correctly. This issue arises because in some browser environments, named DOM elements become properties on the global document object. An attacker with control over the HTML could exploit this to change the CDN domain of tarteaucitron. This issue has been patched in version 1.22.0. Join the discussion | CVE Database V5 | 07/03/2025, 16:26:31 UTC Added: 07/03/2025, 16:39:32 UTC |
Showing 1 to 4 of 4 results