Skip to main content

CWE archive

CWE-1289 CVEs

Programmatic archive

33 CVEs tagged with CWE-12893 Critical, 9 High, 21 Medium, 0 Low, 0 Unrated.

CVE-2026-47729

Published Jul 16, 2026

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulner…

CVSS 6.5 · Medium
evidence mentions
13
Buzz score
46.4
Vendor/product tagsBeta · best-effort

CVE-2026-46644

Published Jul 14, 2026

Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels who…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-50090

Published Jun 12, 2026

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-42462

Published Jun 10, 2026

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of…

CVSS 7.0 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-49942

Published Jun 4, 2026

Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could contain Unicode digits such as the Arabic-Indic One (U+0661…

CVSS 7.3 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-49940

Published Jun 4, 2026

Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Arabic-Indic One (U+0661) were accepted but not properly pars…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-47674

Published May 28, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP ad…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48710

Published May 26, 2026

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because…

CVSS 6.5 · Medium
evidence mentions
28
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-39821

Published May 22, 2026

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns t…

CVSS 9.6 · Critical
evidence mentions
91
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-45191

Published May 10, 2026

Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass. Mask forms like "/00" and…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-45190

Published May 10, 2026

Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass. Inputs containing a trailing newline or n…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-41213

Published Apr 23, 2026

@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character s…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41239

Published Apr 23, 2026

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{...}}` expr…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-33806

Published Apr 15, 2026

Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypassed entirely by prepending a space to the Content-Type header…

CVSS 7.5 · High
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-39972

Published Apr 9, 2026

Mercure is a protocol for pushing data updates to web browsers and other HTTP clients in a battery-efficient way. Prior to 0.22.0, a cache key collision vulnerability in TopicSele…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-62718

Published Apr 9, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules.…

CVSS 6.3 · Medium
evidence mentions
44
Buzz score
49.5
Vendor/product tagsBeta · best-effort

CVE-2026-33810

Published Apr 8, 2026

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constr…

CVSS 8.2 · High
evidence mentions
52
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-34080

Published Apr 7, 2026

xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdrop restrictions. The proxy checks for eavesdrop=tr…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-35039

Published Apr 6, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuilder method which does not properly create unique keys for d…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22569

Published Mar 31, 2026

An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33729

Published Mar 27, 2026

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. In versions prior to 1.13.1, under specific condit…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-33496

Published Mar 26, 2026

ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulne…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-33515

Published Mar 26, 2026

Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem all…

CVSS 6.9 · Medium
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-3563

Published Mar 17, 2026

Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to create or modify Apps or…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-27610

Published Feb 25, 2026

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the `ConfigKeyCache` uses the same cache key for both m…

CVSS 7.0 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2