Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-807

MITRE ↗

CWE-807

6
CRITICAL
19
HIGH
21
MEDIUM
2
LOW
52 CVEs · Page 1/2
10.0
CVE-2026-48491

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Tr

9.8
CVE-2026-32975

OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable gr

9.8
CVE-2025-13926

An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary request

9.8
CVE-2026-24120

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and ca

9.8
CVE-2026-44649

SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode

9.8
CVE-2026-64827

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication byp

8.8
CVE-2026-33068

Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, includ

8.8
CVE-2026-63041

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attack

8.5
CVE-2026-9077

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictio

8.2
CVE-2026-9561

Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source o

8.1
CVE-2026-31892

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.

8.1
CVE-2026-43935

e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset p

8.1
CVE-2026-13059

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role

7.8
CVE-2026-21509 KEV

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a secu

7.8
CVE-2026-25931

vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings

7.8
CVE-2026-21514 KEV

Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a

7.7
CVE-2026-25958

Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possibl

7.5
CVE-2026-20849

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privile

7.5
CVE-2026-29134

SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass

7.5
CVE-2026-34486 KEV

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypas

7.3
CVE-2026-27707

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and

7.3
CVE-2026-41380

OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-

7.3
CVE-2026-41390

OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap

7.1
CVE-2026-32057

OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pair

7.1
CVE-2026-41299

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only

6.7
CVE-2026-0390

Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a sec

6.5
CVE-2025-65328

Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client I

6.5
CVE-2026-23848

MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypas

6.5
CVE-2026-18705

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view

6.5
CVE-2026-53789

rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope o

6.3
CVE-2026-48980

pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environm

6.2
CVE-2019-25544

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providi

6.2
CVE-2019-25594

ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by su

6.2
CVE-2019-25621

Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by pro

6.2
CVE-2019-25711

SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the appli

5.9
CVE-2026-35670

OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies t

5.7
CVE-2026-35655

OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicti

5.4
CVE-2026-32898

OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves

5.4
CVE-2026-16093

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them

5.4
CVE-2026-19579

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request

5.3
CVE-2026-29794

Vikunja is an open-source self-hosted task management platform. Starting in version 0.8 and prior to version 2.2.0, unau

4.9
CVE-2026-1789

A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive informat

4.3
CVE-2026-64934

The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho

4.2
CVE-2026-35617

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that re

4.2
CVE-2026-35624

OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room na

4.2
CVE-2026-53860

OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match

3.7
CVE-2026-58239

SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send

2.9
CVE-2026-41403

OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRe

CVE-2026-39807

Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-sta

CVE-2026-6213

A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check an

Frequently Asked Questions

What is CWE-807?

CWE-807 (CWE-807) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-807?

There are 53 CVE records associated with CWE-807 in our database. Of these, 6 are critical severity, 19 are high severity, and 21 are medium severity.

How can I protect against CWE-807 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-807 using AI-powered security agents.

Detect CWE-807 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-807 vulnerabilities across your infrastructure.

Get Started