Skip to main content

CWE archive

CWE-459 CVEs

Programmatic archive

192 CVEs tagged with CWE-45911 Critical, 57 High, 105 Medium, 19 Low, 0 Unrated.

CVE-2026-42492

Published Jul 28, 2026

Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new XEN_DOMCTL_get_domain_state was…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-7639

Published Jul 10, 2026

Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory acc…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11576

Published Jun 19, 2026

The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-5038

Published Jun 15, 2026

Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using diskStorage. Aborted or malformed multipart uploads leave or…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-53867

Published Jun 12, 2026

Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-33232

Published May 19, 2026

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are vulnerable to an unaut…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-0427

Published May 15, 2026

Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to access these shared resources from anot…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-34263

Published May 12, 2026

Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code exec…

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
28.9

CVE-2026-43395

Published May 8, 2026

In the Linux kernel, the following vulnerability has been resolved: drm/xe/sync: Cleanup partially initialized sync on parse failure xe_sync_entry_parse() can allocate reference…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-66467

Published May 8, 2026

Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket wi…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2026-35361

Published Apr 22, 2026

The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the utility attemp…

CVSS 3.4 · Low
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-6830

Published Apr 21, 2026

nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before…

CVSS 4.8 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-28268

Published Feb 27, 2026

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api t…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-3304

Published Feb 27, 2026

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by send…

CVSS 8.7 · High
evidence mentions
9
Buzz score
42.5
Vendor/product tagsBeta · best-effort

CVE-2026-28196

Published Feb 25, 2026

In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21438

Published Feb 12, 2026

webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTran…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-15331

Published Feb 5, 2026

Tanium addressed an uncontrolled resource consumption vulnerability in Connect.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66675

Published Dec 10, 2025

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.4, fr…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64775

Published Dec 1, 2025

Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion. This issue affects Apache Struts: from 2.0.0 through 6.7.0, fr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-29934

Published Nov 21, 2025

A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.

CVSS 5.3 · Medium

CVE-2025-60730

Published Oct 24, 2025

PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6338

Published Oct 16, 2025

There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period. This issue affects Qt from 5.15…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-20293

Published Sep 24, 2025

A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud (9800-CL) could allow an unauthenticated, remote atta…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-55910

Published Sep 19, 2025

CMSEasy v7.7.8.0 and before is vulnerable to Arbitrary file deletion in database_admin.php.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 192 CVEsPage 1 of 8