Skip to main content

CWE archive

CWE-183 CVEs

Programmatic archive

42 CVEs tagged with CWE-1831 Critical, 15 High, 21 Medium, 5 Low, 0 Unrated.

CVE-2026-66005

Published Jul 24, 2026

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host re…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-16129

Published Jul 18, 2026

A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction._validate_command of the file src/safestclaw/actions/shell…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-46341

Published Jul 16, 2026

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.9.21, the f…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-15625

Published Jul 14, 2026

A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.CheckCommand of the file internal/tools/exec_approval.go. T…

CVSS 2.1 · Low
evidence mentions
12
Buzz score
32.1

CVE-2026-59802

Published Jul 8, 2026

PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containin…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-46608

Published Jun 25, 2026

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s) introduced a configurable CORS origin list in version 4.5.…

CVSS 7.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-50189

Published Jun 24, 2026

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interface on port 9001, reachable fro…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54316

Published Jun 23, 2026

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8918

Published Jun 22, 2026

A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassin…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11525

Published Jun 17, 2026

Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact m…

CVSS 3.7 · Low
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-3490

Published Jun 17, 2026

picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. R…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-46391

Published Jun 5, 2026

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0.0 of @haxtheweb/open-apis, multiple functions conduct subs…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44111

Published May 6, 2026

OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allows callers to read any Markdown files within the workspace…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-43574

Published May 5, 2026

OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval autho…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-29514

Published May 4, 2026

NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with e…

CVSS 8.7 · High
evidence mentions
7
Buzz score
28.8

CVE-2026-41387

Published Apr 28, 2026

OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts that allows package…

CVSS 8.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-42043

Published Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address…

CVSS 7.2 · High
evidence mentions
42
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2026-42042

Published Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantic…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41240

Published Apr 23, 2026

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when f…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-40899

Published Apr 16, 2026

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource co…

CVSS 8.3 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-35649

Published Apr 10, 2026

OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny-all revocations by exploiting empty allowlist handling. Th…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-21915

Published Apr 9, 2026

A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacke…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-4509

Published Mar 21, 2026

A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-32881

Published Mar 20, 2026

ewe is a Gleam web server. ewe is a Gleam web server. Versions 0.6.0 through 3.0.4 are vulnerable to authentication bypass or spoofed proxy-trust headers. Chunked transfer encodin…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort
Showing 1-25 of 42 CVEsPage 1 of 2