Skip to main content

CWE archive

CWE-358 CVEs

Programmatic archive

132 CVEs tagged with CWE-35814 Critical, 45 High, 58 Medium, 15 Low, 0 Unrated.

CVE-2026-46582

Published Jul 22, 2026

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG va…

CVSS 3.7 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-65058

Published Jul 21, 2026

Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-49783

Published Jul 14, 2026

Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-54431

Published Jul 2, 2026

In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requi…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2026-12577

Published Jul 1, 2026

DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-57915

Published Jun 26, 2026

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to v…

CVSS 7.3 · High
evidence mentions
5
Buzz score
32.4

CVE-2026-48797

Published Jun 17, 2026

Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane w…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-50628

Published Jun 12, 2026

A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this se…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-11127

Published Jun 4, 2026

Inappropriate implementation in WebAPKs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted WebAPK. (Chromium sec…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-44475

Published May 27, 2026

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against i…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-44474

Published May 27, 2026

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures defined in TS 33.501 §6…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-44473

Published May 27, 2026

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGA…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-42082

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the concurrent security procedure rules defined in 3GPP TS 33.…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42081

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the UE Security Capabilities received in NGAP PathSwitchRequest…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40597

Published May 22, 2026

Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerability, an attacker can bypass the…

CVSS 7.6 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-44513

Published May 14, 2026

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code executio…

CVSS 8.8 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-45109

Published May 13, 2026

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply…

CVSS 7.5 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-28914

Published May 11, 2026

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP archive may…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-31983

Published May 6, 2026

HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to inject malicious scripts increasing t…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-31970

Published May 6, 2026

HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-22618

Published Apr 16, 2026

A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35679

Published Apr 5, 2026

Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout…

CVSS 3.5 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-29103

Published Mar 19, 2026

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 132 CVEsPage 1 of 6