Threats Tagged 'cwe-923'
View all threats tagged with 'cwe-923'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-923'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-92172 is a high-severity vulnerability in Meta Horizon OS prior to version 66.0.0.733.524. The flaw involves improper restriction of communication channels, allowing an application to receive a privileged PendingIntent with a com.oculus.horizon CallerIdentity via a broadcast receiver. This enables the application to impersonate the com.oculus.horizon package to any endpoint within the OS that relies on CallerIdentity authentication. Join the discussion | CVE Database V5 | 09/30/2026, 20:26:49 UTC Added: 09/30/2026, 20:48:43 UTC |
0 CVE-2026-92173 is a critical vulnerability in Meta Horizon OS prior to version 74.0.0.878.1682. It involves improper restriction of communication channels, allowing an arbitrary application with NotificationListenerService to receive a privileged PendingIntent containing a CallerIdentity from com.oculus.vrshell. This enables impersonation of the com.oculus.vrshell package and other packages signed with the same key for authentication within the OS. Join the discussion | CVE Database V5 | 09/30/2026, 20:26:33 UTC Added: 09/30/2026, 20:48:43 UTC |
CVE Database V5 | 09/29/2026, 17:57:37 UTC Added: 09/29/2026, 18:20:21 UTC | |
0 An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network access to the AP to obtain a valid API session. Join the discussion | CVE Database V5 | 09/28/2026, 16:51:22 UTC Added: 09/28/2026, 17:03:30 UTC |
0 mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30 Join the discussion | CVE Database V5 | 09/28/2026, 12:12:06 UTC Added: 09/28/2026, 12:33:28 UTC |
0 Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings from the upstream template, and together they hand native functionality to untrusted web content. The first is in src-tauri/capabilities/default.json, which grants IPC access with "remote": { "urls": ["https://*.*"] }. That wildcard tells Tauri to accept IPC from any HTTPS origin, not just the site the application was built to wrap. The second is "withGlobalTauri": true in src-tauri/tauri.conf.json, which puts window.__TAURI__.core.invoke() in reach of ordinary page JavaScript. Tauri's access control list only checks plugin commands, the ones prefixed with plugin:. Commands the application registers itself through generate_handler!, known as app commands, are never checked against the ACL. So once an origin holds IPC access, it can call every app command with nothing else standing in the way. Pake registers download_file as an app command, and it does not appear in the permissions list because it does not need to. The practical effect is that any script running on any HTTPS page inside a Pake application can invoke the application's native commands. That includes third-party script the wrapped site loads on its own, such as analytics, advertising, or a compromised CDN. Anyone distributing their own Pake application gets the same access without asking for it. Chained with the path traversal in download_file that is tracked separately as CVE-2026-82635, this reaches arbitrary file write and persistent code execution. Join the discussion | CVE Database V5 | 09/23/2026, 09:56:32 UTC Added: 09/23/2026, 10:03:22 UTC |
0 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead passes ssh_options.host and ssh_options.port for the final target to KnownHosts::trust. In Prompt and AutoAccept modes, a jump host key can therefore be stored for the target address. A machine later presenting the jump host key at the target address can be accepted as the target, allowing interception of user traffic and a newly issued certificate when certificate authentication is used. The native SSH path is unaffected because it tracks each hop separately. This issue is fixed in version 0.27.6. Join the discussion | CVE Database V5 | 09/21/2026, 18:53:56 UTC Added: 09/21/2026, 19:02:22 UTC |
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 09/17/2026, 22:55:56 UTC Added: 09/17/2026, 23:03:02 UTC |
0 OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS into cfg.tlsCfg, but newGRPCDialOptions does not apply cfg.tlsCfg when creating gRPC transport credentials. The environment-only TLS path instead uses credentials.NewTLS with system roots and no configured client certificate, bypassing intended private CA pinning and mutual TLS unless the application also supplies WithTLSCredentials. A network attacker able to intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. This issue is fixed in version 0.21.0. Join the discussion | CVE Database V5 | 09/16/2026, 21:17:00 UTC Added: 09/16/2026, 21:02:19 UTC |
0 OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication. Join the discussion | CVE Database V5 | 09/11/2026, 21:32:33 UTC Added: 09/11/2026, 21:50:28 UTC |
Showing 1 to 10 of 39 results