Skip to main content

CWE archive

CWE-441 CVEs

Programmatic archive

109 CVEs tagged with CWE-44111 Critical, 53 High, 43 Medium, 2 Low, 0 Unrated.

CVE-2026-54663

Published Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves ext…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-43910

Published Jul 28, 2026

Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) is enabled,…

CVSS 8.2 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-17107

Published Jul 24, 2026

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy a…

CVSS 8.5 · High
evidence mentions
9
Buzz score
33.0

CVE-2026-42933

Published Jul 23, 2026

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT s…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-13062

Published Jul 22, 2026

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-c…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47122

Published Jul 21, 2026

Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVer…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-16158

Published Jul 18, 2026

Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimite…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-53514

Published Jul 15, 2026

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox…

CVSS 7.7 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-15183

Published Jul 14, 2026

Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, ex…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-56675

Published Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.5.2, 9router treats loopback requests as trusted and allows /v1/* access without an API key, so a same-host reverse proxy that fo…

CVSS 8.3 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-12879

Published Jul 9, 2026

An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltr…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-55430

Published Jul 8, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the t…

CVSS 5.8 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-49086

Published Jul 6, 2026

Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pub/Sub consumer (DaprPubSubCons…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-46592

Published Jul 6, 2026

Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf producer selects which SOAP operat…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-53931

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-import endpoint axiosRequestMake could be used as a generic HTTP proxy. Before the f…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-50169

Published Jun 22, 2026

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15 20.3.22, and 19.2…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-9595

Published Jun 15, 2026

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-44494

Published Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows…

CVSS 8.7 · High
evidence mentions
51
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-49821

Published Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's bu…

CVSS 7.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-36608

Published Jun 3, 2026

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin interface by accepting its own IP (1…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-0098

Published Jun 1, 2026

In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege w…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-48570

Published Jun 1, 2026

In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This could lead to local escalation of…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48522

Published May 28, 2026

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default Op…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3160

Published May 14, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authentica…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort
Showing 1-25 of 109 CVEsPage 1 of 5