Skip to main content

CWE archive

CWE-400 CVEs

Programmatic archive

3,370 CVEs tagged with CWE-40063 Critical, 1,645 High, 1,523 Medium, 137 Low, 2 Unrated.

CVE-2026-53505

Published Jul 31, 2026

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) filter does not enforce an upper bound on <value> and runs in…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-53504

Published Jul 31, 2026

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated num…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-52857

Published Jul 31, 2026

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in p…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-18358

Published Jul 31, 2026

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypass…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-55497

Published Jul 31, 2026

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decode…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-10695

Published Jul 30, 2026

IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-25039

Published Jul 30, 2026

IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.13 do not limit the length of a connection which could allow…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9322

Published Jul 30, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP req…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-67437

Published Jul 29, 2026

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login hand…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-63119

Published Jul 29, 2026

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in the mcp ge…

CVSS 6.2 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-16543

Published Jul 29, 2026

Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration deni…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-15228

Published Jul 29, 2026

Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collec…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-58182

Published Jul 29, 2026

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-65324

Published Jul 29, 2026

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic S…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-58151

Published Jul 29, 2026

Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59942

Published Jul 28, 2026

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An attacker can crash the PHP proce…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-59941

Published Jul 28, 2026

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bo…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-14981

Published Jul 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTT…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59932

Published Jul 28, 2026

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, a…

CVSS 7.5 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-59933

Published Jul 28, 2026

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, a…

CVSS 7.5 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-54609

Published Jul 28, 2026

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-66299

Published Jul 28, 2026

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-66920

Published Jul 28, 2026

Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affected graph algorithms recursively traversed graph edges, whi…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-66913

Published Jul 28, 2026

Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker could submit a specially crafted ZIP, gzip, or zlib-co…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-42493

Published Jul 28, 2026

Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternativ…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Showing 1-25 of 3,370 CVEsPage 1 of 135