Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

579 CVEs tagged with CWE-20927 Critical, 74 High, 398 Medium, 79 Low, 1 Unrated.

CVE-2026-59943

Published Jul 28, 2026

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rende…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2025-59177

Published Jul 27, 2026

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-56537

Published Jul 27, 2026

HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request d…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-66009

Published Jul 24, 2026

Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public in…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-66008

Published Jul 24, 2026

Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion erro…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-13182

Published Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracl…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64627

Published Jul 21, 2026

Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspectio…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-63748

Published Jul 20, 2026

SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT per…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-8861

Published Jul 17, 2026

IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.  This information could be us…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-23575

Published Jul 17, 2026

HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-56139

Published Jul 6, 2026

Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Undertow Component. The camel-undertow HTTP server consumer exposes a muteException opt…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-49365

Published Jul 6, 2026

Generation of Error Message Containing Sensitive Information vulnerability in Apache Camel Netty HTTP component. The camel-netty-http HTTP server consumer exposes a muteException…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-53906

Published Jul 1, 2026

MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the filename parameter allows writ…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-56331

Published Jun 30, 2026

Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 instead of safe 4xx errors when magic_invite_string is inva…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-47775

Published Jun 26, 2026

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, the OAuth2 HTTP filter's encrypt()/decrypt() f…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49979

Published Jun 24, 2026

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smtpHost a…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59872

Published Jun 17, 2026

HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, then it may be possible to obtain command execution on the s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-47248

Published Jun 12, 2026

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-40997

Published Jun 11, 2026

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through except…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-41730

Published Jun 10, 2026

Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: S…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52611

Published Jun 4, 2026

HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's J…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52606

Published Jun 4, 2026

HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expecte…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9794

Published May 28, 2026

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Mark…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-42459

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to validate the supi path parameter in six GET handlers of the nud…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 579 CVEsPage 1 of 24