Skip to main content

CWE archive

CWE-1284 CVEs

Programmatic archive

363 CVEs tagged with CWE-128422 Critical, 155 High, 158 Medium, 28 Low, 0 Unrated.

CVE-2026-54890

Published Jul 27, 2026

Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation.…

CVSS 8.2 · High
evidence mentions
5
Buzz score
30.9

CVE-2026-59532

Published Jul 27, 2026

Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59531

Published Jul 27, 2026

Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-58662

Published Jul 27, 2026

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are re…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-66374

Published Jul 25, 2026

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-11721

Published Jul 22, 2026

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-10822

Published Jul 22, 2026

If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-32665

Published Jul 22, 2026

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-47667

Published Jul 21, 2026

CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from the first 4 bytes of an An…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-59695

Published Jul 17, 2026

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitraril…

CVSS 8.3 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-59694

Published Jul 17, 2026

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, de…

CVSS 8.3 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-59252

Published Jul 17, 2026

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitim…

CVSS 8.2 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-57364

Published Jul 13, 2026

Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions &amp; More better-paym…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-57023

Published Jul 9, 2026

An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthent…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59930

Published Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values witho…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-59879

Published Jul 8, 2026

Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and up…

CVSS 8.7 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-59997

Published Jul 8, 2026

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensur…

CVSS 4.2 · Medium
evidence mentions
4
Buzz score
36.1
Vendor/product tagsBeta · best-effort

CVE-2026-43928

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment adapter accepts PayPal IPN callbacks and credits the IPN-s…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-54234

Published Jul 6, 2026

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the r…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2022-4990

Published Jul 3, 2026

** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass security validation and access restr…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2022-4989

Published Jul 3, 2026

** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access unintended memory regions via crafte…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55952

Published Jul 2, 2026

The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before pass…

CVSS 8.2 · High
evidence mentions
8
Buzz score
40.0
Vendor/product tagsBeta · best-effort

CVE-2026-57623

Published Jul 2, 2026

Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
21.0
Showing 1-25 of 363 CVEsPage 1 of 15