Skip to main content

CWE archive

CWE-146 CVEs

Programmatic archive

9 CVEs tagged with CWE-1461 Critical, 6 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-22266

Published Feb 19, 2026

Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communication Channel vulnerability in the REST API. A high privilege…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-53192

Published Aug 18, 2025

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all version…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-20237

Published Aug 14, 2025

A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local att…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-20329

Published Oct 23, 2024

A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to execute operating system commands as root…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-4055

Published Nov 19, 2022

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1