Skip to main content

CWE archive

CWE-134 CVEs

Programmatic archive

395 CVEs tagged with CWE-13497 Critical, 155 High, 120 Medium, 23 Low, 0 Unrated.

CVE-2026-6390

Published Jul 23, 2026

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2024-58366

Published Jul 18, 2026

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can sup…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-15809

Published Jul 15, 2026

A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on…

CVSS 7.8 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-15680

Published Jul 13, 2026

Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46465

Published Jul 3, 2026

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release ve…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57877

Published Jun 26, 2026

An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of extern…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-10828

Published Jun 16, 2026

A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vu…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-10262

Published Jun 16, 2026

Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authentic…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-12174

Published Jun 13, 2026

A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler.…

CVSS 7.4 · High
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2026-6250

Published Jun 11, 2026

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpre…

CVSS 7.0 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-6242

Published Jun 6, 2026

An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of externally supplied parameters within formatting f…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-6241

Published Jun 6, 2026

An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-7835

Published May 21, 2026

A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorre…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-6474

Published May 14, 2026

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before Postg…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44407

Published May 7, 2026

A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corruption and remote denial of service.

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6539

Published Apr 30, 2026

Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by c…

CVSS 4.6 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-3008

Published Apr 27, 2026

Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.

CVSS 6.6 · Medium
evidence mentions
5
Buzz score
34.4

CVE-2026-3509

Published Mar 24, 2026

An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-33210

Published Mar 20, 2026

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of s…

CVSS 8.3 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2025-30269

Published Feb 11, 2026

A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerab…

CVSS 0.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-64157

Published Feb 10, 2026

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all vers…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 395 CVEsPage 1 of 16