CWE-821
8 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-821page 1 of 1
- CVE-2022-1931HIGHCVSS 8.1EG 8.12022-05-31
Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.
- CVE-2023-5088MEDIUMCVSS 6.4EG 6.42023-11-03
A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual d…
- CVE-2024-1739CRITICALCVSS 9.1EG 7.52024-04-16
lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multip…
- CVE-2024-1902HIGHCVSS 7.5EG 7.52024-04-10
lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name without proper authorization. The vulnerability stems from the lack of validation to check if a user is still part of an orga…
- CVE-2024-4154MEDIUMCVSS 6.5EG 7.12024-05-21
In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to. Specifically, an unprivileged user can send a PATCH request to the project's endpoint wi…
- CVE-2024-4278MEDIUMCVSS 5.5EG 5.52024-09-26
An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by …
- CVE-2024-5755MEDIUMCVSS 5.3EG 5.32024-06-27
In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the creation of multiple accounts with essentially the same email address (e.g., 'attacker123@…
- CVE-2024-6657MEDIUMCVSS 6.5EG 6.52024-10-11
A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuously connect and disconnect to the peripheral. A hard reset is required to recover the peripheral device.
Map vulnerabilities like CWE-821 to your infrastructure
EchelonGraph correlates every CVE — across CWE-821 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →