Skip to main content

CWE archive

CWE-115 CVEs

Programmatic archive

28 CVEs tagged with CWE-1154 Critical, 9 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2026-42004

Published Jun 25, 2026

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted,…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-12491

Published Jun 17, 2026

A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically EXIF orientat…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-68113

Published Dec 16, 2025

ALTCHA is privacy-first software for captcha and bot protection. A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable repl…

CVSS 6.5 · Medium

CVE-2025-55303

Published Aug 19, 2025

Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54584

Published Jul 30, 2025

GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19.1 and below, an attacker can craft a malicious Git packfil…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32908

Published Apr 14, 2025

A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :authority, and :path, which may allow a user to cause a den…

CVSS 7.5 · High

CVE-2024-11169

Published Mar 20, 2025

An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling file uploads. An…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-22870

Published Mar 12, 2025

Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com…

CVSS 4.4 · Medium
evidence mentions
6
Buzz score
37.5

CVE-2025-25069

Published Feb 7, 2025

A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be s…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32228

Published Apr 11, 2024

A firmware bug which may lead to misinterpretation of data in the AMC2-4WCF and AMC2-2WCF allowing an adversary to grant access to the last authorized user.

CVSS 4.6 · Medium

CVE-2023-32260

Published Mar 19, 2024

Misinterpretation of Input vulnerability in OpenText™ Service Management Automation X (SMAX), OpenText™ Asset Management X (AMX), and OpenText™ Hybrid Cloud Management X (HCMX) pr…

CVSS 6.5 · Medium

CVE-2023-0880

Published Feb 17, 2023

Misinterpretation of Input in GitHub repository thorsten/phpmyfaq prior to 3.1.11.

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20915

Published Oct 10, 2022

A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to ca…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21672

Published Jan 10, 2022

make-ca is a utility to deliver and manage a complete PKI configuration for workstations and servers. Starting with version 0.9 and prior to version 1.10, make-ca misinterprets Mo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0207

Published Jan 15, 2021

An improper interpretation conflict of certain data between certain software components within the Juniper Networks Junos OS devices does not allow certain traffic to pass through…

CVSS 7.5 · High

CVE-2020-29511

Published Dec 14, 2020

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-29510

Published Dec 14, 2020

The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-29509

Published Dec 14, 2020

The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 28 CVEsPage 1 of 2