Skip to main content

CWE archive

CWE-1327 CVEs

Programmatic archive

19 CVEs tagged with CWE-13275 Critical, 4 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2026-55641

Published Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-0481

Published May 15, 2026

Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potenti…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-42503

Published May 6, 2026

gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen is given a value without an explicit host (e.g. :8080), or…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-24015

Published Mar 9, 2026

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, w…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-28395

Published Mar 5, 2026

OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server that treats…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-21528

Published Feb 10, 2026

Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-11538

Published Nov 13, 2025

A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all…

CVSS 6.8 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2025-61934

Published Oct 23, 2025

A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. The vulnerability allows an unauthenticated remote attacker…

CVSS 9.3 · Critical

CVE-2025-55322

Published Sep 24, 2025

Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3621

Published Jul 15, 2025

Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilities: * Improper Neutraliz…

CVSS 9.4 · Critical

CVE-2024-47176

Published Sep 26, 2024

CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services a…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
32.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-36105

Published May 27, 2024

dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Prior to versions 1.6.15, 1.7.15, and 1…

CVSS 5.3 · Medium

CVE-2023-5398

Published Apr 17, 2024

Server receiving a malformed message based on a list of IPs resulting in heap corruption causing a denial of service. See Honeywell Security Notification for recommendations on up…

CVSS 5.9 · Medium
Showing 1-19 of 19 CVEsPage 1 of 1