Skip to main content

CWE archive

CWE-184 CVEs

Programmatic archive

173 CVEs tagged with CWE-18428 Critical, 73 High, 53 Medium, 19 Low, 0 Unrated.

CVE-2026-74886

Published Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-73650

Published Aug 13, 2026

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScr…

CVSS 8.2 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-73484

Published Aug 13, 2026

Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. A…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-73492

Published Aug 12, 2026

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_ur…

CVSS 2.3 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-73491

Published Aug 12, 2026

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_ur…

CVSS 2.3 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-70466

Published Aug 12, 2026

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions,…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-73078

Published Aug 11, 2026

Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookma…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-72779

Published Aug 11, 2026

Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entr…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-17630

Published Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-71259

Published Aug 5, 2026

ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validat…

CVSS 8.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-70470

Published Aug 4, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCo…

CVSS 9.5 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-69263

Published Aug 4, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but pa…

CVSS 8.7 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-18174

Published Jul 29, 2026

@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header contains two or more comma separated entries, the parser tr…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-50251

Published Jul 22, 2026

In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-ci…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-47392

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/pytho…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-63108

Published Jul 20, 2026

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting co…

CVSS 7.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-16129

Published Jul 18, 2026

A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction._validate_command of the file src/safestclaw/actions/shell…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-62203

Published Jul 17, 2026

OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with low…

CVSS 7.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-52888

Published Jul 15, 2026

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql us…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-48736

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and…

CVSS 6.9 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-45753

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupp…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-45066

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-15625

Published Jul 14, 2026

A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.CheckCommand of the file internal/tools/exec_approval.go. T…

CVSS 2.1 · Low
evidence mentions
12
Buzz score
32.1

CVE-2026-62200

Published Jul 13, 2026

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reach…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 1-25 of 173 CVEsPage 1 of 7