VYPR

CWE-807

Reliance on Untrusted Inputs in a Security Decision

BaseIncompleteLikelihood: High

Description

The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.

Hierarchy (View 1000)

CVEs mapped to this weakness (114)

page 2 of 6
  • CVE-2019-10844CriApr 4, 2019
    risk 0.57cvss 9.8epss 0.02

    nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environment variable, which might be untrusted.

  • CVE-2026-82533CriSep 8, 2026
    risk 0.55cvss 9.6epss 0.01

    DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the…

  • CVE-2026-9077HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.

  • CVE-2026-87479HigSep 9, 2026
    risk 0.54cvss 8.3epss 0.00

    Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium…

  • CVE-2026-34486HigKEVApr 9, 2026
    risk 0.54cvss 7.5epss 0.07

    Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or…

  • CVE-2026-13059HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.00

    An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters. The issue affects find, update, delete, and…

  • CVE-2026-9561HigJul 14, 2026
    risk 0.53cvss 8.2epss 0.00

    Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header…

  • CVE-2024-13974HigJul 21, 2025
    risk 0.53cvss 8.1epss 0.07

    A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.

  • CVE-2024-5754HigSep 13, 2024
    risk 0.53cvss 8.2epss 0.00

    BT: Encryption procedure host vulnerability

  • CVE-2021-36777HigMar 9, 2022
    risk 0.53cvss 8.1epss 0.01

    A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects:…

  • CVE-2024-29039CriJun 28, 2024
    risk 0.52cvss 9.0epss 0.01

    tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to manipulate tpm2_checkquote outputs by altering the TPML_PCR_SELECTION in the PCR input file. As a result, digest values are incorrectly mapped to PCR slots and…

  • CVE-2026-25931HigFeb 9, 2026
    risk 0.51cvss 7.8epss 0.00

    vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value defaults to true (package.json) and is…

  • CVE-2024-28829HigAug 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privileges.

  • CVE-2023-0009HigJun 14, 2023
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows enables a local user to execute programs with elevated privileges.

  • CVE-2026-63041HigAug 26, 2026
    risk 0.50cvss 8.8epss 0.01

    Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly. This…

  • CVE-2026-33068HigMar 20, 2026
    risk 0.50cvss 8.8epss 0.01

    Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, including the repo-controlled .claude/settings.json, before determining whether to display the workspace trust confirmation dialog. A malicious repository could set…

  • CVE-2026-29610HigMar 5, 2026
    risk 0.50cvss 8.8epss 0.01

    OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintended binaries by manipulating PATH environment variables through node-host execution or project-local bootstrapping. Attackers with authenticated access to…

  • CVE-2026-54730HigAug 18, 2026
    risk 0.49cvss —epss 0.01

    authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome…

  • CVE-2026-29134HigApr 2, 2026
    risk 0.49cvss 7.5epss 0.00

    SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions.

  • CVE-2026-20849HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.