Skip to main content

CWE archive

CWE-453 CVEs

Programmatic archive

18 CVEs tagged with CWE-4534 Critical, 6 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2026-0082

Published Jun 17, 2026

In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could lead to local escala…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41330

Published Apr 21, 2026

OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to properly enforce proxy, TLS, Docker, and Git TLS controls. Atta…

CVSS 2.0 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-61926

Published Oct 9, 2025

Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Reviewbot component caused inbound webhook requests to be vali…

CVSS 4.6 · Medium

CVE-2025-48563

Published Sep 4, 2025

In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead to local escalation of privilege with…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-47945

Published May 17, 2025

Donetick an open-source app for managing tasks and chores. Prior to version 0.1.44, the application uses JSON Web Tokens (JWT) for authentication, but the signing secret has a wea…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-30206

Published Apr 15, 2025

Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration,…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2024-41255

Published Jul 31, 2024

filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init func…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39916

Published Jul 12, 2024

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the NFS configuration in /etc/exports generated by the installer…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27516

Published Oct 12, 2023

An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to un…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-47197

Published Jan 19, 2023

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47196

Published Jan 19, 2023

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47195

Published Jan 19, 2023

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-47194

Published Jan 19, 2023

An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default installations of Ghost allow non-administrator users to inject…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46831

Published Dec 8, 2022

In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allowed TeamCity project administrators to access AWS resources…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3262

Published Dec 8, 2022

A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1