CWE-821
13 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-821page 1 of 1
- CVE-2022-1931HIGHCVSS 8.1EG 8.12022-05-31
Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.
- CVE-2023-5088MEDIUMCVSS 6.4EG 6.42023-11-03
A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual d…
- CVE-2024-1739CRITICALCVSS 9.1EG 7.52024-04-16
lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multip…
- CVE-2024-1902HIGHCVSS 7.5EG 7.52024-04-10
lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name without proper authorization. The vulnerability stems from the lack of validation to check if a user is still part of an orga…
- CVE-2024-4154MEDIUMCVSS 6.5EG 7.12024-05-21
In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projects they do not have access to. Specifically, an unprivileged user can send a PATCH request to the project's endpoint wi…
- CVE-2024-4278MEDIUMCVSS 5.5EG 5.52024-09-26
An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by …
- CVE-2024-5755MEDIUMCVSS 5.3EG 5.32024-06-27
In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the creation of multiple accounts with essentially the same email address (e.g., 'attacker123@…
- CVE-2024-58131MEDIUMCVSS 4.0EG 4.02025-04-06
FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a malicious node (that has modified the codebase to allow a large min_seal_time value) joins a blockchain network.
- CVE-2024-58132MEDIUMCVSS 4.0EG 4.02025-04-06
In chainmaker-go (aka ChainMaker) before 2.3.6, multiple updates to a single node's configuration can cause other normal nodes to perform concurrent read and write operations on a map, leading to a panic.
- CVE-2024-58133MEDIUMCVSS 4.0EG 4.02025-04-06
In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarting this node, concurrent writes by logger.go to a map are mishandled. Creating other logs simultaneously can lead to a …
- CVE-2024-6657MEDIUMCVSS 6.5EG 6.52024-10-11
A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuously connect and disconnect to the peripheral. A hard reset is required to recover the peripheral device.
- CVE-2024-7043HIGHCVSS 8.8EG 8.12025-03-20
An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the GE…
- CVE-2026-21919MEDIUMCVSS 6.5EG 6.52026-04-09
An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to cause a complete Denial-of-Service (DoS) of the management p…
Map vulnerabilities like CWE-821 to your infrastructure
EchelonGraph correlates every CVE — across CWE-821 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →