Skip to main content

CWE archive

CWE-114 CVEs

Programmatic archive

26 CVEs tagged with CWE-1146 Critical, 11 High, 8 Medium, 1 Low, 0 Unrated.

CVE-2026-26945

Published Mar 18, 2026

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10,…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-29046

Published Mar 6, 2026

TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environment variables…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-36251

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls.…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-36250

Published Nov 13, 2025

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to impro…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-46370

Published Nov 13, 2025

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control vulnerability. A low privileged attacker with local access could potentially explo…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-1950

Published Apr 22, 2025

IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an un…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-56347

Published Mar 18, 2025

IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-56346

Published Mar 18, 2025

IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-0160

Published Feb 28, 2025

IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 th…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-44168

Published Sep 17, 2024

A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app may be able to modify…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8207

Published Aug 27, 2024

In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25021

Published Feb 22, 2024

IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-Force ID: 281320.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25736

Published Oct 30, 2023

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer c…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40299

Published Oct 4, 2023

Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4487

Published Sep 5, 2023

GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to e…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6024

Published Jan 20, 2021

Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local p…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6014

Published Nov 2, 2020

Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11081

Published Jul 10, 2020

osquery before version 4.4.0 enables a privilege escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user m…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11075

Published May 27, 2020

In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer s…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2