Skip to main content

CWE archive

CWE-471 CVEs

Programmatic archive

36 CVEs tagged with CWE-4713 Critical, 16 High, 15 Medium, 2 Low, 0 Unrated.

CVE-2026-54267

Published Jun 22, 2026

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, to optim…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-44798

Published May 28, 2026

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to…

CVSS 7.1 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-8492

Published May 19, 2026

Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing. This issue affects Translate Drupal with…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-57708

Published Jun 25, 2025

An issue in OneTrust SDK v.6.33.0 allows a local attacker to cause a denial of service via the Object.setPrototypeOf, __proto__, and Object.assign components. NOTE: this is disput…

CVSS 5.7 · Medium

CVE-2025-33136

Published May 22, 2025

IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9876

Published Apr 30, 2025

: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.…

CVSS 8.5 · High

CVE-2024-55551

Published Mar 19, 2025

An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45672

Published Jan 23, 2025

IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive privileges granted to the agent. which could also cause a d…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51462

Published Jan 17, 2025

IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter values due to improper input validation of assumed immutable dat…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34517

Published May 7, 2024

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46232

Published Oct 25, 2023

era-compiler-vyper is the EraVM Vyper compiler for zkSync Era, a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to era-compiler-vype version 1.3.10, a bug…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43697

Published Oct 9, 2023

Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows an unprivileged remote attacker to make the site unable to load necessary strings via changing file path…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2904

Published Jun 7, 2023

The External Visitor Manager portal of HID’s SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API). A…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25893

Published Dec 21, 2022

The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability l…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-3288

Published Oct 17, 2022

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-1561

Published Aug 1, 2022

Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters correctly, allowing a malicious user to alter the backend U…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21824

Published Feb 24, 2022

Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passin…

CVSS 8.2 · High

CVE-2021-24046

Published Jan 14, 2022

A logic flaw in Ray-Ban® Stories device software allowed some parameters like video capture duration limit to be modified through the Facebook View application. This issue affecte…

CVSS 5.3 · Medium

CVE-2021-42701

Published Nov 5, 2021

An attacker could prepare a specially crafted project file that, if opened, would attempt to connect to the cloud and trigger a man in the middle (MiTM) attack. This could allow a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37193

Published Sep 14, 2021

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). An unauthenticated attacker in the same network of the affected system could manipul…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37177

Published Sep 14, 2021

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). The status provided by the syslog clients managed by the affected software can be ma…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26268

Published Dec 10, 2020

In affected versions of TensorFlow the tf.raw_ops.ImmutableConst operation returns a constant tensor created from a memory mapped file which is assumed immutable. However, if the…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26245

Published Nov 27, 2020

npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 36 CVEsPage 1 of 2