Skip to main content

CWE archive

CWE-480 CVEs

Programmatic archive

8 CVEs tagged with CWE-4802 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-44722

Published Jul 17, 2026

pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py caused…

CVSS 6.2 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-15043

Published Jul 14, 2026

DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
34.4

CVE-2026-48497

Published Jun 26, 2026

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured wi…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43114

Published May 6, 2026

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry New test case fails unexpectedly wh…

CVSS 9.4 · Critical
evidence mentions
11
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-4748

Published Apr 1, 2026

A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address range(s) involved to be silentl…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52985

Published Jul 11, 2025

A Use of Incorrect Operator vulnerability in the Routing Engine firewall of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to bypass security…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35190

Published May 17, 2024

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asteris…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1