Skip to main content

CWE archive

CWE-354 CVEs

Programmatic archive

171 CVEs tagged with CWE-35411 Critical, 78 High, 75 Medium, 7 Low, 0 Unrated.

CVE-2026-56416

Published Jul 22, 2026

In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-16317

Published Jul 21, 2026

Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data record…

CVSS 8.3 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-13385

Published Jul 15, 2026

An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router d…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-9653

Published Jul 14, 2026

A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-8720

Published Jun 25, 2026

wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of the input. When the supplied key…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-50021

Published Jun 25, 2026

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is absent from the lockfile resoluti…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50128

Published Jun 24, 2026

Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has a feature to let websites credit authors of their arti…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-48028

Published Jun 24, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming activities signed with Linked…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-49230

Published Jun 19, 2026

Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass.  This issu…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
25.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-11694

Published Jun 16, 2026

A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-34182

Published Jun 9, 2026

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, le…

CVSS 9.1 · Critical
evidence mentions
8
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2026-34181

Published Jun 9, 2026

Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanis…

CVSS 7.4 · High
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2026-8597

Published May 14, 2026

Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to a…

CVSS 6.4 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-32148

Published Apr 30, 2026

Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex s…

CVSS 8.9 · High
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-40323

Published Apr 18, 2026

SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architecture. In versions 6.0.0 through 6.0.2, a soundness vulnerabil…

CVSS 8.9 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-32105

Published Apr 17, 2026

xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets wh…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-5479

Published Apr 10, 2026

In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in wolfSSL_EVP_CipherFinal (and related EVP cipher finalization functions) fails to verify the authentication ta…

CVSS 7.6 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-5504

Published Apr 9, 2026

A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repeated decryption queries with modified ciphertext. In previo…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-26928

Published Apr 2, 2026

SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dynamic library. JAR files are correctly verified based on a li…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-33026

Published Mar 30, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-32303

Published Mar 20, 2026

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration…

CVSS 7.6 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-28498

Published Mar 16, 2026

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library conce…

CVSS 8.2 · High
evidence mentions
12
Buzz score
38.6
Vendor/product tagsBeta · best-effort

CVE-2026-32600

Published Mar 16, 2026

xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-g…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 171 CVEsPage 1 of 7