Skip to main content

CWE archive

CWE-253 CVEs

Programmatic archive

23 CVEs tagged with CWE-2533 Critical, 11 High, 7 Medium, 2 Low, 0 Unrated.

CVE-2026-53090

Published Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix ld_{abs,ind} failure path analysis in subprogs Usage of ld_{abs,ind} instructions got extended into…

CVSS 7.8 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-5818

Published Jun 24, 2026

Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Core's verification of the MCU FW d…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46419

Published May 14, 2026

Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-43863

Published May 4, 2026

mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-35340

Published Apr 22, 2026

A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit code during recursive operations. The final exit code is dete…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-35339

Published Apr 22, 2026

The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple files. The final return value is determined solely by the…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-0648

Published Jan 27, 2026

The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layers/OSEK/tx_osek.c) when handling the retu…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11839

Published Oct 16, 2025

A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. Th…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
42.0
Vendor/product tagsBeta · best-effort

CVE-2025-57767

Published Aug 28, 2025

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is received with an Authorization header…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54090

Published Jul 23, 2025

A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32475

Published Apr 18, 2024

Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enabled, a request containing a `host`/`:authority` header longer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49286

Published Dec 4, 2023

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attac…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34449

Published Jun 14, 2023

ink! is an embedded domain specific language to write smart contracts in Rust for blockchains built on the Substrate framework. Starting in version 4.0.0 and prior to version 4.2.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37625

Published Aug 5, 2021

Skytable is an open source NoSQL database. In versions prior to 0.6.4 an incorrect check of return value of the accept function in the run-loop for a TCP socket/TLS socket/TCP+TLS…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6107

Published Oct 15, 2020

An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause an uninitializ…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7474

Published May 12, 2017

It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to rest…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1