Skip to main content

CWE archive

CWE-400 CVEs

Programmatic archive

3,362 CVEs tagged with CWE-40063 Critical, 1,640 High, 1,520 Medium, 137 Low, 2 Unrated.

CVE-2026-67437

Published Jul 29, 2026

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login hand…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-63119

Published Jul 29, 2026

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StdioTransport and MCP::Client::Stdio in the mcp ge…

CVSS 6.2 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-16543

Published Jul 29, 2026

Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration deni…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-15228

Published Jul 29, 2026

Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collec…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-58182

Published Jul 29, 2026

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9,…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65324

Published Jul 29, 2026

Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory. This issue affects Apache Traffic S…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-58151

Published Jul 29, 2026

Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This issue affects Apache Traffic Server: from 8.0.0 through 8.1…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59942

Published Jul 28, 2026

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An attacker can crash the PHP proce…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-59941

Published Jul 28, 2026

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bo…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-14981

Published Jul 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTT…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-59932

Published Jul 28, 2026

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, a…

CVSS 7.5 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-59933

Published Jul 28, 2026

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, a…

CVSS 7.5 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-54609

Published Jul 28, 2026

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-66299

Published Jul 28, 2026

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-66920

Published Jul 28, 2026

Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affected graph algorithms recursively traversed graph edges, whi…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-66913

Published Jul 28, 2026

Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker could submit a specially crafted ZIP, gzip, or zlib-co…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-42493

Published Jul 28, 2026

Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternativ…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2025-63913

Published Jul 27, 2026

An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' fu…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55685

Published Jul 27, 2026

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on th…

CVSS 8.7 · High
evidence mentions
6
Buzz score
24.5

CVE-2026-43806

Published Jul 27, 2026

A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.6. A local attacker may be able to cause a denial of service.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43768

Published Jul 27, 2026

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected s…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-28932

Published Jul 27, 2026

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Ta…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-66144

Published Jul 24, 2026

Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service attack if a huge polic…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 3,362 CVEsPage 1 of 135