Skip to main content

CWE archive

CWE-283 CVEs

Programmatic archive

23 CVEs tagged with CWE-2833 Critical, 5 High, 13 Medium, 2 Low, 0 Unrated.

CVE-2026-44707

Published May 26, 2026

Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email conf…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-44562

Published May 15, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint allows users with the wo…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40337

Published Apr 18, 2026

The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given task with one of the DEV or IO capability is able to intera…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-4269

Published Mar 16, 2026

A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to co…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-29788

Published Mar 6, 2026

TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 30, c…

CVSS 8.4 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-27486

Published Feb 21, 2026

OpenClaw is a personal AI assistant. In versions 2026.2.13 and below of the OpenClaw CLI, the process cleanup uses system-wide process enumeration and pattern matching to terminat…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-26016

Published Feb 19, 2026

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-0598

Published Feb 6, 2026

A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. The APIs do not properly verify whether a conversation identi…

CVSS 4.2 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-20912

Published Jan 22, 2026

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release…

CVSS 9.1 · Critical
evidence mentions
8
Buzz score
40.0
Vendor/product tagsBeta · best-effort

CVE-2025-12815

Published Nov 6, 2025

An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote us…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2025-36091

Published Nov 3, 2025

IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ow…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-9822

Published Sep 3, 2025

SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usu…

CVSS 5.5 · Medium

CVE-2025-47940

Published May 20, 2025

TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, admini…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-1007

Published Feb 19, 2025

In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Cont…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-27903

Published Jul 8, 2024

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-1853

Published Mar 14, 2024

Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x80002048 IOCTL code of the zam64.sys and zamguard64.sys drivers.

CVSS 5.5 · Medium

CVE-2023-30544

Published Apr 24, 2023

Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This p…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-24501

Published Aug 9, 2021

The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user was authorized to perform critical operations such as modifyi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24500

Published Aug 9, 2021

Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated.…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8554

Published Jan 21, 2021

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Addi…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0
Showing 1-23 of 23 CVEsPage 1 of 1