CWE-807: CWE-807

19
Total CVEs
5
Critical
13
High
8.2
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
5
2025
7
2024
3
2023
2
2022
1

Top Affected Vendors

1 Microsoft 4
2 Paloaltonetworks 1
3 Franklioxygen 1
4 Zephyrproject 1
5 Opensuse 1
6 Cyberark 1
7 Sophos 1
8 63moons 1
9 Tpm2 Tools Project 1
10 Cube 1

All CWE-807 CVEs (19)

CVE-2025-12487
9.8

This vulnerability allows remote attackers to execute arbitrary code on oobabooga text-generation-webui installations without authentication. Attacker...

Nov 6, 2025
CVE-2025-12488
9.8

This vulnerability allows remote attackers to execute arbitrary code on oobabooga text-generation-webui installations without authentication. Attacker...

Nov 6, 2025
CVE-2025-49827
9.8

This vulnerability allows attackers to bypass IAM authentication in Conjur by manipulating AWS-signed headers to redirect validation requests to malic...

Jul 15, 2025
CVE-2025-1126
9.3

This vulnerability in Lexmark Print Management Client allows attackers to bypass security decisions by providing malicious input. It affects organizat...

Feb 11, 2025
CVE-2024-29039
9.0

This vulnerability in tpm2-tools allows attackers to manipulate TPM quote verification results by tampering with PCR input files. Attackers can make t...

Jun 28, 2024
CVE-2024-55354
8.8

This vulnerability in Lucee CFML engine allows attackers who can place files on the server to bypass security protections and execute arbitrary code. ...

Apr 8, 2025
CVE-2024-5754
8.2

This vulnerability in Zephyr RTOS Bluetooth stack allows attackers to bypass encryption procedures, potentially enabling unauthorized access to Blueto...

Sep 13, 2024
CVE-2024-13974
8.1

This vulnerability in Sophos Firewall's Up2Date component allows attackers who control the firewall's DNS environment to achieve remote code execution...

Jul 21, 2025
CVE-2021-36777
8.1

This vulnerability in openSUSE Build Service login proxy allows attackers to create fake login forms that capture user credentials in plain text and s...

Mar 9, 2022
CVE-2026-21514
KEV 7.8

This vulnerability in Microsoft Office Word allows attackers to bypass local security features by manipulating untrusted inputs. It affects users runn...

Feb 10, 2026
CVE-2026-21509
KEV EPSS 13.4% 7.8

This vulnerability in Microsoft Office allows an attacker to bypass local security features by manipulating untrusted inputs. It affects users running...

Jan 26, 2026
CVE-2023-0009
7.8

This CVE describes a local privilege escalation vulnerability in Palo Alto Networks GlobalProtect app on Windows. It allows a local user to execute pr...

Jun 14, 2023
CVE-2026-25958
7.7

Cube semantic layer versions 0.27.19 through 1.5.12, 1.4.1 and earlier, and 1.0.13 and earlier contain an API token validation vulnerability that allo...

Feb 9, 2026
CVE-2026-20849
7.5

This Windows Kerberos vulnerability allows authenticated attackers to elevate privileges over a network by exploiting reliance on untrusted inputs in ...

Jan 13, 2026
CVE-2024-51561
7.5

This vulnerability allows authenticated attackers to bypass OTP verification in Aero's authentication system by intercepting and manipulating response...

Nov 4, 2024
CVE-2022-24400
7.5

This vulnerability in TETRA authentication allows a man-in-the-middle attacker who can predict the MS challenge RAND2 to set the session key DCK to ze...

Oct 19, 2023
CVE-2025-53717
7.0

This vulnerability in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally by exploiting re...

Oct 14, 2025
CVE-2021-29479
7.0

This vulnerability allows attackers to poison web caches by manipulating the X-Forwarded-Host header in Ratpack applications. It enables redirect cach...

Jun 29, 2021
CVE-2026-23848
6.5

This vulnerability allows unauthenticated attackers to bypass IP-based rate limiting in MyTube by spoofing the X-Forwarded-For header. This enables un...

Jan 19, 2026

About CWE-807 (CWE-807)

Our database tracks 19 CVEs classified as CWE-807, with 5 rated critical and 13 rated high severity. The average CVSS score for CWE-807 vulnerabilities is 8.2.

External reference: View CWE-807 on MITRE CWE →

Monitor CWE-807 Vulnerabilities

Get alerted when new CWE-807 CVEs affect your infrastructure.

Start Monitoring Free