Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,719 CVEs tagged with CWE-201,604 Critical, 4,989 High, 5,605 Medium, 515 Low, 6 Unrated.

CVE-2026-47196

Published Jun 12, 2026

Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not reject an empty result. Adding a rule containing only whitesp…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-50633

Published Jun 12, 2026

A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deploym…

CVSS 8.1 · High
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-50632

Published Jun 12, 2026

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution ca…

CVSS 8.1 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-50628

Published Jun 12, 2026

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this se…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-47370

Published Jun 12, 2026

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Com…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-47369

Published Jun 12, 2026

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate priv…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-47367

Published Jun 12, 2026

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injecti…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-12034

Published Jun 11, 2026

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer pr…

CVSS 8.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-12009

Published Jun 11, 2026

Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to p…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-47181

Published Jun 11, 2026

PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the password reset endpoint allows any authenticated user to ch…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49982

Published Jun 11, 2026

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It is byp…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53723

Published Jun 11, 2026

Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses in…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49214

Published Jun 11, 2026

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48998

Published Jun 11, 2026

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53901

Published Jun 11, 2026

Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler attempted to remove an attacker-supplied id from $params bef…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-49218

Published Jun 10, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could r…

CVSS 7.5 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2024-21944

Published Jun 10, 2026

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or contr…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
30.9

CVE-2026-48110

Published Jun 10, 2026

Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and server message handlers decoded attacker-controlled SSH strings…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48108

Published Jun 10, 2026

Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string rules as deliberately as Open…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48107

Published Jun 10, 2026

Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server cou…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-46679

Published Jun 10, 2026

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer t…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46669

Published Jun 10, 2026

OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library's try_honest_pairing_check fu…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 301-325 of 12,719 CVEsPage 13 of 509