Skip to main content

CWE archive

CWE-440 CVEs

Programmatic archive

41 CVEs tagged with CWE-4403 Critical, 8 High, 27 Medium, 3 Low, 0 Unrated.

CVE-2026-8806

Published Jun 19, 2026

Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-42752

Published Jun 15, 2026

Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-49316

Published May 29, 2026

Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the motorcycle's a…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-42534

Published May 20, 2026

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the…

CVSS 6.9 · Medium
evidence mentions
9
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2026-41136

Published Apr 22, 2026

free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Prior to version 1.4.3, the `…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-35040

Published Apr 9, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in the allowedAud, allowedIss, allowedSub, allowedJti, or all…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-8850

Published Oct 30, 2025

In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to disable 2FA without requiring a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52953

Published Jul 11, 2025

An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sen…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6211

Published Jul 10, 2025

A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document chunks. Th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3044

Published Jul 7, 2025

A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downl…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-40555

Published May 13, 2025

A vulnerability has been identified in APOGEE PXC+TALON TC Series (BACnet) (All versions). Affected devices start sending unsolicited BACnet broadcast messages after processing a…

CVSS 5.3 · Medium

CVE-2025-46712

Published May 8, 2025

Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25), Erl…

CVSS 3.7 · Low

CVE-2023-26819

Published Apr 19, 2025

cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-56202

Published Mar 6, 2025

Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are rec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27401

Published Mar 4, 2025

Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of Tuleap, the issue has a limited impact, it will mostly lea…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27094

Published Mar 3, 2025

Tuleap is an open-source suite designed to improve software development management and collaboration. A malicious user with access to a tracker could force-reset certain field con…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47762

Published Oct 3, 2024

Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment variables, for example APP_CONFIG_backend_listen_port=7007,…

CVSS 5.8 · Medium

CVE-2024-7246

Published Aug 6, 2024

It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the backend such that other clients see failed requests. It's als…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38806

Published Jul 18, 2024

Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially…

CVSS 3.9 · Low

CVE-2024-32971

Published May 2, 2024

Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. The affected versions of Apollo Router contain a bug tha…

CVSS 9.0 · Critical

CVE-2024-30246

Published Mar 29, 2024

Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could exploit this issue on purpose to delete information on the…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 41 CVEsPage 1 of 2