Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,718 CVEs tagged with CWE-201,603 Critical, 4,989 High, 5,605 Medium, 515 Low, 6 Unrated.

CVE-2026-54299

Published Jun 22, 2026

Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime whe…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55602

Published Jun 22, 2026

http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or ho…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53537

Published Jun 22, 2026

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7165

Published Jun 22, 2026

The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of other users’ information without r…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-12787

Published Jun 21, 2026

A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part of the component testConnection Endpoint. The man…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
27.9

CVE-2026-56340

Published Jun 20, 2026

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default,…

CVSS 8.7 · High
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-56325

Published Jun 20, 2026

Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscore characters in app_id to act as…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
17.5

CVE-2026-56228

Published Jun 20, 2026

Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can s…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-48774

Published Jun 19, 2026

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MCP `run_sql_readonly` tool violates its documented read-only…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-21768

Published Jun 19, 2026

The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious cont…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-39998

Published Jun 19, 2026

Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue af…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-58175

Published Jun 18, 2026

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `ENTITY_RESOLUTION_ALLOWLIST` ma…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-12569

Published Jun 18, 2026

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of…

CVSS 9.3 · Critical
evidence mentions
8
Buzz score
67.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-50196

Published Jun 17, 2026

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eureka prior to versions 4.2.0 a…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-48055

Published Jun 17, 2026

Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in S…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2025-48643

Published Jun 17, 2026

In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2026-0142

Published Jun 16, 2026

In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional ex…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12191

Published Jun 14, 2026

A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Modul…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-45013

Published Jun 12, 2026

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password reset flow that constructs the reset URL using `req.hostname…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-54133

Published Jun 12, 2026

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versio…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47196

Published Jun 12, 2026

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not reject an empty result. Adding a rule containing only whitesp…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0
Showing 276-300 of 12,718 CVEsPage 12 of 509