Skip to main content

CWE archive

CWE-470 CVEs

Programmatic archive

75 CVEs tagged with CWE-47016 Critical, 40 High, 18 Medium, 1 Low, 0 Unrated.

CVE-2026-53666

Published Jul 27, 2026

React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-63317

Published Jul 24, 2026

Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three…

CVSS 5.6 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-65608

Published Jul 23, 2026

Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_use…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-13187

Published Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploit…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13181

Published Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution,…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44174

Published Jul 16, 2026

Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collection queries, allowing attacke…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-46562

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algo…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-58659

Published Jul 15, 2026

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled…

CVSS 8.4 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-44795

Published Jul 10, 2026

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization wh…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-40008

Published Jul 10, 2026

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pipe processor reads a fully qualified Java class name and in…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-55153

Published Jul 1, 2026

mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementat…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24246

Published Jul 1, 2026

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulner…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-13772

Published Jun 30, 2026

IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class names via Class.forName() and invokes their constructors with…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57284

Published Jun 24, 2026

Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to i…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48517

Published Jun 22, 2026

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deserialization includes MessagePackSerializerOptions.ThrowIfDeser…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49287

Published Jun 19, 2026

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026-41175 was incomplete. It addressed the issue in the query…

CVSS 7.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-48817

Published Jun 17, 2026

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and loo…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-46718

Published Jun 2, 2026

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Us…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-34216

Published May 19, 2026

CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update endpoint accepted a fully qualified class name directly fro…

CVSS 6.6 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-8178

Published May 8, 2026

An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connecti…

CVSS 9.2 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-44339

Published May 8, 2026

PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves unresolved tool names against module global…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42027

Published May 4, 2026

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description:  The Exte…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-41175

Published Apr 22, 2026

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints,…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-25239

Published Apr 4, 2026

Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attac…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
25.4
Showing 1-25 of 75 CVEsPage 1 of 3