The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
Volume of CVEs assigned to CWE-807 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
85 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21509HIGH Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. | Jan 26, 2026 | 7.8 | 94 | YES | NO |
CVE-2026-21514HIGH Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. | Feb 10, 2026 | 7.8 | 70 | YES | NO |
CVE-2026-34486HIGH Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomc | Apr 9, 2026 | 7.5 | 58 | NO | YES |
CVE-2026-24120CRITICAL vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can | May 4, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-44649CRITICAL SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice model | May 29, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-9561HIGH Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclips | Jul 14, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-6213CRITICAL A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server sid | May 8, 2026 | 10.0 | 37 | NO | NO |
CVE-2026-48491CRITICAL Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an | Jun 23, 2026 | 10.0 | 36 | NO | NO |
CVE-2026-13059HIGH An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient vali | Jul 22, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-32975CRITICAL OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable group display names instead of stable group identifiers. Attac | Mar 29, 2026 | 9.8 | 35 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.