Skip to main content

CWE archive

CWE-1286 CVEs

Programmatic archive

88 CVEs tagged with CWE-12861 Critical, 49 High, 34 Medium, 4 Low, 0 Unrated.

CVE-2026-57026

Published Jul 9, 2026

An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticat…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55767

Published Jun 23, 2026

Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matches…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48059

Published Jun 12, 2026

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in…

CVSS 8.7 · High
evidence mentions
13
Buzz score
39.4
Vendor/product tagsBeta · best-effort

CVE-2026-50131

Published Jun 10, 2026

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding…

CVSS 8.6 · High
evidence mentions
1
Buzz score
16.5
Public PoC observed

CVE-2025-8873

Published Jun 4, 2026

On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may dete…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-25720

Published Jun 3, 2026

Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated at…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2021-4479

Published Jun 2, 2026

Dräger Atlan A350 versions 1.00 up to and including 1.01 contains an improper input handling vulnerability that allows attackers to cause a denial of service by sending specifical…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2019-25723

Published Jun 2, 2026

Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows external attackers to cause a denial of service by sending sp…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-10099

Published May 29, 2026

XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_server.py that allows attackers to cause corrupted applicati…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-7307

Published May 19, 2026

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious i…

CVSS 7.5 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2026-0983

Published May 18, 2026

Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-42579

Published May 13, 2026

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's DNS codec does not enforce RFC 1035 domain name constraints…

CVSS 7.5 · High
evidence mentions
10
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2026-6918

Published May 5, 2026

In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.

CVSS 8.7 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-6442

Published Apr 16, 2026

Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could exploit th…

CVSS 8.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-40198

Published Apr 10, 2026

Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_ipv6() does not check that uncompressed IPv6 addresses (wit…

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-33778

Published Apr 9, 2026

An Improper Validation of Syntactic Correctness of Input vulnerability in the IPsec library used by kmd and iked of Juniper Networks Junos OS on SRX Series and MX Series allows a…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-34835

Published Apr 2, 2026

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33218

Published Mar 25, 2026

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode po…

CVSS 7.5 · High
evidence mentions
8
Buzz score
36.5
Vendor/product tagsBeta · best-effort

CVE-2026-27889

Published Mar 25, 2026

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanit…

CVSS 7.5 · High
evidence mentions
8
Buzz score
36.5
Vendor/product tagsBeta · best-effort

CVE-2026-20114

Published Mar 25, 2026

A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access mana…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
25.4
Showing 1-25 of 88 CVEsPage 1 of 4