Skip to main content

CWE archive

CWE-345 CVEs

Programmatic archive

654 CVEs tagged with CWE-34584 Critical, 261 High, 267 Medium, 42 Low, 0 Unrated.

CVE-2026-12383

Published Jul 27, 2026

A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-39155

Published Jul 23, 2026

Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broa…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-15615

Published Jul 23, 2026

Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and replay assertions indefinitely.

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-15612

Published Jul 23, 2026

Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-52688

Published Jul 23, 2026

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50248

Published Jul 22, 2026

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44690

Published Jul 22, 2026

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC proc…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-13188

Published Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chaine…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62517

Published Jul 21, 2026

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Di…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-44584

Published Jul 20, 2026

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the email update functionality fails to invalidate the existin…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-12724

Published Jul 20, 2026

The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-10724

Published Jul 20, 2026

The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, all…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49284

Published Jul 17, 2026

SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path does not enforce the IdP selected…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-54496

Published Jul 17, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar mu…

CVSS 9.3 · Critical
evidence mentions
7
Buzz score
30.8

CVE-2026-49212

Published Jul 17, 2026

Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop k…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-63094

Published Jul 17, 2026

SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instanc…

CVSS 7.6 · High
evidence mentions
6
Buzz score
26.0

CVE-2026-62215

Published Jul 17, 2026

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-44434

Published Jul 16, 2026

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless reset injection t…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-33731

Published Jul 16, 2026

WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification byp…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-53536

Published Jul 16, 2026

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endpoint verified the supplied JWT against the shared signing s…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-53516

Published Jul 15, 2026

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit acc…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-53514

Published Jul 15, 2026

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox…

CVSS 7.7 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-53512

Published Jul 15, 2026

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_toke…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-45337

Published Jul 15, 2026

Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorization plugin treats any authenticated session as the owner of…

CVSS 7.6 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort
Showing 1-25 of 654 CVEsPage 1 of 27