Skip to main content

CWE archive

CWE-233 CVEs

Programmatic archive

31 CVEs tagged with CWE-2333 Critical, 11 High, 16 Medium, 1 Low, 0 Unrated.

CVE-2026-0515

Published Jul 14, 2026

Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-32998

Published May 28, 2026

This vulnerability in Veeam Service Provider Console allows for remote code execution.

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-33585

Published May 13, 2026

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authenticated tenant user via an unexpi…

CVSS 3.8 · Low
evidence mentions
1
Buzz score
11.9

CVE-2018-25233

Published Mar 30, 2026

WebDrive 18.00.5057 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the username field d…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-2370

Published Mar 30, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 affecting Jira Connect installations th…

CVSS 8.1 · High
evidence mentions
6
Buzz score
35.5
Vendor/product tagsBeta · best-effort

CVE-2023-20514

Published Feb 11, 2026

Improper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to functions in the trusted execution environ…

CVSS 8.7 · High

CVE-2026-22626

Published Jan 30, 2026

Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can cause abnormal device behavior by crafting specific messag…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-55080

Published Oct 15, 2025

In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55078

Published Oct 14, 2025

In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region. Vulnerable system calls…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52970

Published Aug 12, 2025

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthentic…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-1419

Published Nov 17, 2024

A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to send a maliciou…

CVSS 5.9 · Medium

CVE-2024-9329

Published Sep 30, 2024

In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40819

Published Aug 6, 2024

ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-7261

Published Jun 7, 2024

Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation via a malicious file. (Chromium securi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33433

Published May 14, 2024

Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20306

Published Mar 27, 2024

A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root o…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24525

Published Feb 29, 2024

An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the URL.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-26549

Published Mar 27, 2023

The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successful exploitation of this vulnerability may affect confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45478

Published Mar 2, 2023

Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Au…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-45477

Published Mar 2, 2023

Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Au…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2