Skip to main content

CWE archive

CWE-40 CVEs

Programmatic archive

5 CVEs tagged with CWE-401 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-25039

Published Jul 20, 2026

Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that wo…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-27615

Published Feb 25, 2026

ADB Explorer is a fluent UI for ADB on Windows. In versions prior to Beta 0.9.26022, ADB-Explorer allows the `ManualAdbPath` settings variable, which determines the path of the AD…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-32103

Published Apr 15, 2025

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accessible by SMB at UNC share pathnames,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44548

Published Dec 23, 2021

An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from th…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1