Skip to main content

CWE archive

CWE-405 CVEs

Programmatic archive

46 CVEs tagged with CWE-4050 Critical, 25 High, 20 Medium, 1 Low, 0 Unrated.

CVE-2025-32394

Published Jun 26, 2026

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in AITextS…

CVSS 5.3 · Medium

CVE-2026-54224

Published Jun 18, 2026

UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile on instances with many registered users, an authenticated at…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-8594

Published May 30, 2026

Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific line br…

CVSS 6.2 · Medium
evidence mentions
4
Buzz score
32.6

CVE-2026-45557

Published May 19, 2026

Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-44296

Published May 12, 2026

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enable…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-35665

Published Apr 10, 2026

OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request bodies with permissive limits of 1MB and 30-second timeout…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-35626

Published Apr 9, 2026

OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-25611

Published Feb 10, 2026

A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-24324

Published Feb 10, 2026

SAP BusinessObjects Business Intelligence Platform (AdminTools) allows an authenticated attacker with user privileges to execute a specific query in AdminTools that could cause th…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-0485

Published Feb 10, 2026

SAP BusinessObjects BI Platform allows an unauthenticated attacker to send specially crafted requests that could cause the Content Management Server (CMS) to crash and automatical…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-22775

Published Jan 15, 2026

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.1.0 to 5.6.1, certain inputs can cause devalue.…

CVSS 7.5 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-22774

Published Jan 15, 2026

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From 5.3.0 to 5.6.1, certain inputs can cause devalue.…

CVSS 7.5 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2025-68480

Published Dec 22, 2025

Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2,…

CVSS 5.3 · Medium

CVE-2025-42876

Published Dec 9, 2025

Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single comp…

CVSS 7.1 · High

CVE-2025-42874

Published Dec 9, 2025

SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input val…

CVSS 7.9 · High

CVE-2025-42873

Published Dec 9, 2025

SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate prop…

CVSS 5.9 · Medium

CVE-2025-66506

Published Dec 4, 2025

Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to 1.8.3, function identity.extractIssuerURL split…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49643

Published Dec 1, 2025

An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to pot…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8677

Published Oct 22, 2025

Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-26516

Published Sep 19, 2025

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Service vulnerability. Successful exploit could allow an una…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-31987

Published Aug 14, 2025

HCL Connections Docs may mishandle validation of certain uploaded documents leading to denial of service due to resource exhaustion.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 46 CVEsPage 1 of 2