Skip to main content

CWE archive

CWE-328 CVEs

Programmatic archive

90 CVEs tagged with CWE-32810 Critical, 15 High, 33 Medium, 32 Low, 0 Unrated.

CVE-2026-15605

Published Jul 13, 2026

A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component…

CVSS 2.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-41879

Published Jul 10, 2026

R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin credentials. Critically, this pa…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-14742

Published Jul 5, 2026

A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-14738

Published Jul 5, 2026

A security flaw has been discovered in exo-explore exo up to 1.0.71. Affected is the function _image_cache_key of the file src/exo/worker/engines/mlx/vision.py of the component Vi…

CVSS 2.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-14630

Published Jul 4, 2026

A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function get_conversation_history of the file 08_agentic_system/me…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-10540

Published Jul 1, 2026

The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtaine…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13455

Published Jun 30, 2026

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53692

Published Jun 30, 2026

Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographically broken algorithm and lacks salting, attackers who obtain…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13510

Published Jun 28, 2026

A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.ts of th…

CVSS 2.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-13482

Published Jun 28, 2026

A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file sky/users/server.py of the component User ID Handler. The…

CVSS 2.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-54266

Published Jun 22, 2026

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, Angular'…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-48488

Published Jun 8, 2026

phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been vulnerabl…

CVSS 2.7 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-11481

Published Jun 8, 2026

A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the co…

CVSS 1.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-11479

Published Jun 8, 2026

A vulnerability has been found in yoanbernabeu grepai 0.35.0. This issue affects some unknown processing of the file indexer/chunker.go of the component Qdrant Backend. Such manip…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-11330

Published Jun 5, 2026

A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObservationContentHash of the file src/services/sqlite/observatio…

CVSS 2.0 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-11329

Published Jun 5, 2026

A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key of the file src/Runtime/python/torch_onnxmlir/src/torch_on…

CVSS 2.0 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-36182

Published Jun 4, 2026

GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a brute…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-10814

Published Jun 4, 2026

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component…

CVSS 1.1 · Low
evidence mentions
8
Buzz score
28.5
Vendor/product tagsBeta · best-effort

CVE-2026-10813

Published Jun 4, 2026

A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executin…

CVSS 1.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-10812

Published Jun 4, 2026

A vulnerability was detected in zilliztech GPTCache up to 0.1.44. Affected by this issue is the function BufferedReader.peek of the file gptcache/processor/pre.py of the component…

CVSS 1.1 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-10804

Published Jun 4, 2026

A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler.…

CVSS 1.1 · Low
evidence mentions
7
Buzz score
27.3
Vendor/product tagsBeta · best-effort

CVE-2026-10803

Published Jun 4, 2026

A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest Comp…

CVSS 1.1 · Low
evidence mentions
7
Buzz score
31.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-10801

Published Jun 4, 2026

A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the compone…

CVSS 1.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-10800

Published Jun 4, 2026

A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the comp…

CVSS 2.0 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-10783

Published Jun 4, 2026

A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation…

CVSS 1.1 · Low
evidence mentions
7
Buzz score
31.8
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 90 CVEsPage 1 of 4