Skip to main content

CWE archive

CWE-1173 CVEs

Programmatic archive

9 CVEs tagged with CWE-11731 Critical, 2 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2024-58360

Published Jul 16, 2026

stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can creat…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-33454

Published Apr 27, 2026

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out'…

CVSS 9.4 · Critical
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-33674

Published Mar 26, 2026

PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No know…

CVSS 2.0 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-48490

Published May 30, 2025

Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be…

CVSS 6.6 · Medium

CVE-2023-30949

Published Jul 26, 2023

A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29091

Published Apr 14, 2023

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos 9110, and Exyn…

CVSS 6.8 · Medium

CVE-2022-1414

Published Oct 19, 2022

3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject scripts and possibly gain acces…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1640

Published Jul 17, 2020

An improper use of a validation framework when processing incoming genuine BGP packets within Juniper Networks RPD (routing protocols process) daemon allows an attacker to crash R…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1