Skip to main content

CWE archive

CWE-475 CVEs

Programmatic archive

15 CVEs tagged with CWE-4750 Critical, 6 High, 8 Medium, 1 Low, 0 Unrated.

CVE-2026-8391

Published May 12, 2026

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.

CVSS 5.3 · Medium
evidence mentions
29
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-34379

Published Apr 6, 2026

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9,…

CVSS 7.1 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-21690

Published Jan 7, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versi…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-10569

Published Mar 20, 2025

A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3099

Published Jun 6, 2024

A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw can lead to Denial of Service (…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20380

Published Apr 18, 2024

A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29207

Published May 20, 2022

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, multiple TensorFlow operations misbehave in eager mode when the resou…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7925

Published Nov 23, 2020

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1