Skip to main content

CWE archive

CWE-420 CVEs

Programmatic archive

37 CVEs tagged with CWE-4205 Critical, 15 High, 13 Medium, 4 Low, 0 Unrated.

CVE-2026-43505

Published May 1, 2026

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activati…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-40217

Published Apr 10, 2026

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

CVSS 8.8 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-35388

Published Apr 2, 2026

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

CVSS 2.5 · Low
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-25916

Published Feb 9, 2026

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2025-41727

Published Jan 27, 2026

A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to perform privileged operations and gain administrator access.

CVSS 7.8 · High

CVE-2025-67303

Published Jan 5, 2026

An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the application storing i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62001

Published Dec 18, 2025

BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance monitoring scope and performance. Certain exclusion patterns…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66432

Published Nov 30, 2025

In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date.

CVSS 5.0 · Medium

CVE-2025-56558

Published Oct 29, 2025

The Dyson MQTT server (2022 and possibly later) allows publications and subscriptions by a client that has the correct values of AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESS…

CVSS 3.0 · Low

CVE-2025-62820

Published Oct 23, 2025

Slack Nebula before 1.9.7 mishandles CIDR in some configurations and thus accepts arbitrary source IP addresses within the Nebula network.

CVSS 4.9 · Medium

CVE-2025-53967

Published Oct 8, 2025

Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacha…

CVSS 8.0 · High

CVE-2025-8557

Published Sep 11, 2025

An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attacker with access to a device on the local Lenovo XClarity Orc…

CVSS 8.7 · High

CVE-2025-59033

Published Sep 8, 2025

The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code…

CVSS 7.4 · High

CVE-2025-54351

Published Aug 3, 2025

In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54309

Published Jul 18, 2025

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin acces…

CVSS 9.0 · Critical
evidence mentions
7
Buzz score
58.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-52968

Published Jun 23, 2025

xdg-open in xdg-utils through 1.2.1 can send requests containing SameSite=Strict cookies, which can facilitate CSRF. (For example, xdg-open could be modified to, by default, assoc…

CVSS 2.7 · Low

CVE-2025-52921

Published Jun 23, 2025

In Innoshop through 0.4.1, an authenticated attacker could exploit the File Manager functions in the admin panel to achieve code execution on the server, by uploading a crafted fi…

CVSS 9.9 · Critical

CVE-2022-28693

Published Feb 14, 2025

Unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local…

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2024-10081

Published Nov 6, 2024

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Aut…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8038

Published Oct 2, 2024

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network name…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2