Skip to main content

CWE archive

CWE-460 CVEs

Programmatic archive

22 CVEs tagged with CWE-4600 Critical, 4 High, 15 Medium, 3 Low, 0 Unrated.

CVE-2026-48524

Published May 28, 2026

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown k…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40583

Published Apr 21, 2026

UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance pr…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-33481

Published Mar 26, 2026

Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. Syft versions before v1.42.3 would not properly clean…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-20118

Published Mar 11, 2026

A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series with…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-69652

Published Mar 6, 2026

GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due…

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59399

Published Sep 15, 2025

libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error message generation.

CVSS 3.1 · Low

CVE-2025-32439

Published Apr 15, 2025

pleezer is a headless Deezer Connect player. Hook scripts in pleezer can be triggered by various events like track changes and playback state changes. In versions before 0.16.0, t…

CVSS 6.5 · Medium

CVE-2025-30157

Published Mar 21, 2025

Envoy is a cloud-native high-performance edge/middle/service proxy. Prior to 1.33.1, 1.32.4, 1.31.6, and 1.30.10, Envoy's ext_proc HTTP filter is at risk of crashing if a local re…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12289

Published Dec 12, 2024

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20354

Published Mar 27, 2024

A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of ser…

CVSS 4.7 · Medium

CVE-2024-0316

Published Jan 15, 2024

Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple reque…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46393

Published Oct 27, 2023

gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4744

Published Mar 30, 2023

A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGIST…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3301

Published Sep 26, 2022

Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-22150

Published Feb 4, 2022

A memory corruption vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A specially-crafted PDF document can trigger an exception w…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14304

Published Sep 15, 2020

A memory disclosure flaw was found in the Linux kernel's ethernet drivers, in the way it read data from the EEPROM of the device. This flaw allows a local user to read uninitializ…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9592

Published Apr 16, 2018

openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1