Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Tr
OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable gr
An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary request
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and ca
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication byp
Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, includ
Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attack
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictio
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source o
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.
e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset p
An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a secu
vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a
Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possibl
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privile
SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypas
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and
OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-
OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap
OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pair
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a sec
Mega-Fence (webgate-lib.*) 25.1.914 and prior trusts the first value of the X-Forwarded-For (XFF) header as the client I
MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypas
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view
rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope o
pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environm
Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providi
ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by su
Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by pro
SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the appli
OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies t
OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicti
OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request
Vikunja is an open-source self-hosted task management platform. Starting in version 0.8 and prior to version 2.2.0, unau
A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive informat
The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, witho
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that re
OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room na
OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match
SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send
OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRe
Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-sta
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check an
Frequently Asked Questions
What is CWE-807?
CWE-807 (CWE-807) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-807?
There are 53 CVE records associated with CWE-807 in our database. Of these, 6 are critical severity, 19 are high severity, and 21 are medium severity.
How can I protect against CWE-807 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-807 using AI-powered security agents.
Detect CWE-807 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-807 vulnerabilities across your infrastructure.
Get Started