Skip to main content

CWE archive

CWE-116 CVEs

Programmatic archive

479 CVEs tagged with CWE-11664 Critical, 157 High, 216 Medium, 42 Low, 0 Unrated.

CVE-2026-59727

Published Jul 27, 2026

Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is appli…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-64647

Published Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may r…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-55730

Published Jul 24, 2026

Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12496

Published Jul 24, 2026

Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allo…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-51677

Published Jul 17, 2026

An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior.

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-63397

Published Jul 16, 2026

remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary JavaScript or TypeScript. The m…

CVSS 7.1 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-15809

Published Jul 15, 2026

A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on…

CVSS 7.8 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-46637

Published Jul 14, 2026

Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-46628

Published Jul 14, 2026

Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-62184

Published Jul 13, 2026

luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to i…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-58487

Published Jul 13, 2026

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, due to unsafe handling of the local-part of registered email addresses,…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49844

Published Jul 10, 2026

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Lo…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-55659

Published Jul 10, 2026

Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled values into the page and into inl…

CVSS 7.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-59833

Published Jul 9, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, b…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-59895

Published Jul 8, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-54893

Published Jul 6, 2026

URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API request URL by interpolating the sender's email address into th…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.6

CVE-2026-49091

Published Jul 1, 2026

Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted inpu…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47206

Published Jun 26, 2026

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
18.9

CVE-2026-28898

Published Jun 25, 2026

swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40011

Published Jun 25, 2026

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometh…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-55570

Published Jun 24, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are serialize…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54699

Published Jun 24, 2026

Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL UR…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-54013

Published Jun 23, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI patched SVG XSS in user profile images and webhook pr…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 479 CVEsPage 1 of 20