Skip to main content

CWE archive

CWE-1188 CVEs

Programmatic archive

310 CVEs tagged with CWE-118888 Critical, 125 High, 85 Medium, 11 Low, 1 Unrated.

CVE-2026-65881

Published Jul 28, 2026

Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read…

CVSS N/A · Unrated
evidence mentions
1
Buzz score
11.9

CVE-2026-9680

Published Jul 28, 2026

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on a…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-47668

Published Jul 23, 2026

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-55708

Published Jul 22, 2026

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already co…

CVSS 3.1 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-47393

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) tha…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-62415

Published Jul 21, 2026

Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthen…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-60024

Published Jul 17, 2026

Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthen…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-62185

Published Jul 13, 2026

Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-61439

Published Jul 11, 2026

PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass t…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-54800

Published Jul 9, 2026

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ship…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-14474

Published Jul 7, 2026

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole object…

CVSS 8.8 · High
evidence mentions
6
Buzz score
29.5

CVE-2026-56285

Published Jun 29, 2026

Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute v…

CVSS 7.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-46386

Published Jun 26, 2026

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the defau…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-55454

Published Jun 24, 2026

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default —…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54158

Published Jun 24, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54067

Published Jun 24, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSnippet()…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54066

Published Jun 24, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the /export/ route…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48509

Published Jun 22, 2026

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50519

Published Jun 19, 2026

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-20265

Published Jun 17, 2026

In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0134

Published Jun 16, 2026

In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information disclos…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54359

Published Jun 12, 2026

MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. When this setting is disabled, state-changing requests such…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44892

Published Jun 12, 2026

Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler`…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 310 CVEsPage 1 of 13