The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22.
oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This
oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This
A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management
Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a prot
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely
1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauth
Improper Restriction of Excessive Authentication Attempts, Client-Side Enforcement of Server-Side Security, Reliance on
Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an aut
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry re
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving
TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the conte
The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3
IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted
Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a us
By utilizing software-defined radios and a custom low-latency processing pipeline, RF signals with spoofed location data
Anubis is a tool that allows administrators to protect bots against AI scrapers through bot-checking heuristics and a pr
A reliance on untrusted input for a security decision in the GlobalProtect app on Windows devices potentially enables a
tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to man
Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b
BT: Encryption procedure host vulnerability
Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. A
In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability coul
Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote att
Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been ide
A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local u
A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set sess
A reliance on untrusted inputs in a security decision could be exploited by a privileged user to configure the Gallaghe
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service all
A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an au
A Reliance on Untrusted Inputs in a Security Decision vulnerability in Rancher allows users in the cluster to act as oth
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify
Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a user supplied `X-Forwarded-Host` heade
The command-line "safety" package for Python has a potential security issue. There are two Python characteristics that a
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing
Frequently Asked Questions
What is CWE-807?
CWE-807 (CWE-807) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-807?
There are 95 CVE records associated with CWE-807 in our database. Of these, 13 are critical severity, 35 are high severity, and 37 are medium severity.
How can I protect against CWE-807 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-807 using AI-powered security agents.
Detect CWE-807 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-807 vulnerabilities across your infrastructure.
Get Started