Skip to main content

CWE archive

CWE-1025 CVEs

Programmatic archive

12 CVEs tagged with CWE-10251 Critical, 4 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2025-71377

Published Jul 16, 2026

stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-9800

Published Jun 25, 2026

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access…

CVSS 8.1 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2026-48860

Published Jun 10, 2026

Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist. The ine…

CVSS 7.5 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-40880

Published Apr 21, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allo…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40227

Published Apr 10, 2026

In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that has a null element.

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21691

Published Jan 7, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versi…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-32464

Published Apr 9, 2025

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patt…

CVSS 6.8 · Medium

CVE-2025-2888

Published Mar 27, 2025

During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp v…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2887

Published Mar 27, 2025

During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the targe…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-25306

Published Mar 10, 2025

Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate the relation between the `id` and `url` fields of ActivityPu…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27839

Published Mar 8, 2025

operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification r…

CVSS 3.2 · Low
Showing 1-12 of 12 CVEsPage 1 of 1