Skip to main content

CWE archive

CWE-425 CVEs

Programmatic archive

235 CVEs tagged with CWE-42534 Critical, 75 High, 115 Medium, 11 Low, 0 Unrated.

CVE-2026-21760

Published Jul 17, 2026

HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-23573

Published Jul 17, 2026

HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 imple…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-13533

Published Jun 29, 2026

A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the compo…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-10521

Published Jun 23, 2026

An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9610

Published Jun 22, 2026

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34028

Published Jun 15, 2026

The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not protected by an authorization scheme. An unauthenticated atta…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-11986

Published Jun 11, 2026

A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-8205

Published May 21, 2026

Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42297

Published May 9, 2026

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's Con…

CVSS 8.5 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-7500

Published Apr 30, 2026

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha…

CVSS 5.4 · Medium
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2024-58343

Published Apr 16, 2026

Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id.

CVSS 4.3 · Medium

CVE-2026-35029

Published Apr 6, 2026

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A use…

CVSS 8.7 · High
evidence mentions
9
Buzz score
42.5
Vendor/product tagsBeta · best-effort

CVE-2026-29909

Published Mar 30, 2026

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and prop…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15381

Published Mar 27, 2026

In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenti…

CVSS 7.1 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-4900

Published Mar 26, 2026

A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-34056

Published Mar 26, 2026

OpenEMR is a free and open source electronic health records and medical practice management application. A Broken Access Control vulnerability in OpenEMR up to and including versi…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-34051

Published Mar 26, 2026

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have an improper access control on the Import/Ex…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-33217

Published Mar 25, 2026

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these AC…

CVSS 7.1 · High
evidence mentions
8
Buzz score
36.5
Vendor/product tagsBeta · best-effort

CVE-2026-4532

Published Mar 22, 2026

A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-22732

Published Mar 19, 2026

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue aff…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-32867

Published Mar 19, 2026

OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number and upload arbitrary files via 'Portal/EEOC/DocumentUploadP…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-15587

Published Mar 16, 2026

Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an administrator's password by directly accessing a specific resourc…

CVSS 8.6 · High
evidence mentions
5
Buzz score
27.9

CVE-2026-25679

Published Mar 6, 2026

url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

CVSS 7.5 · High
evidence mentions
245
Buzz score
49.5
Vendor/product tagsBeta · best-effort

CVE-2026-1978

Published Feb 6, 2026

A vulnerability was detected in kalyan02 NanoCMS up to 0.4. Affected by this issue is some unknown functionality of the file /data/pagesdata.txt of the component User Information…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2025-52024

Published Jan 23, 2026

A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testing tools to unauthenticated users. By accessing specific URL…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 235 CVEsPage 1 of 10