Skip to main content

CWE archive

CWE-1288 CVEs

Programmatic archive

29 CVEs tagged with CWE-12881 Critical, 14 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2026-15943

Published Jul 17, 2026

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC i…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-42982

Published Jul 14, 2026

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
7
Buzz score
38.3

CVE-2026-14781

Published Jul 5, 2026

A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker incorrectly synchronizes the email_verified claim. When an OIDC identity provider is configured with tr…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-46117

Published May 28, 2026

In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() Sashiko points out that the user can…

CVSS 7.8 · High
evidence mentions
11
Buzz score
41.4
Vendor/product tagsBeta · best-effort

CVE-2026-9689

Published May 27, 2026

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers…

CVSS 4.2 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-31709

Published May 1, 2026

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate the whole DACL before rewriting it in cifsacl build_sec_desc() and id_mode_to_cifs_acl(…

CVSS 8.8 · High
evidence mentions
20
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-43001

Published May 1, 2026

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the proje…

CVSS 7.9 · High
evidence mentions
7
Buzz score
40.3
Vendor/product tagsBeta · best-effort

CVE-2026-31488

Published Apr 22, 2026

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not skip unrelated mode changes in DSC validation Starting with commit 17ce8a6907f7 ("drm…

CVSS 7.8 · High
evidence mentions
15
Buzz score
47.7
Vendor/product tagsBeta · best-effort

CVE-2022-50976

Published Feb 2, 2026

A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB.

CVSS 7.7 · High

CVE-2025-10929

Published Oct 30, 2025

Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables.This issue affects Reverse Proxy Header:…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-9999

Published Sep 5, 2025

Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker to execute unau…

CVSS 7.6 · High

CVE-2025-46722

Published May 29, 2025

vLLM is an inference and serving engine for large language models (LLMs). In versions starting from 0.7.0 to before 0.9.0, in the file vllm/multimodal/hasher.py, the MultiModalHas…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12093

Published May 22, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modifi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2885

Published Mar 27, 2025

Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metada…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8305

Published Oct 21, 2024

prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause multiple secondaries crashing…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39515

Published Oct 9, 2024

An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated n…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5953

Published Jun 18, 2024

A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log…

CVSS 5.7 · Medium

CVE-2024-27375

Published Jun 5, 2024

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is…

CVSS 6.7 · Medium

CVE-2024-27371

Published Jun 5, 2024

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is…

CVSS 6.7 · Medium

CVE-2024-31140

Published Mar 28, 2024

In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31136

Published Mar 28, 2024

In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-25951

Published Mar 9, 2024

A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6245

Published Dec 8, 2023

The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For example, if the payload is `record { * ; empty }` and the can…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 29 CVEsPage 1 of 2