Skip to main content

CWE archive

CWE-488 CVEs

Programmatic archive

32 CVEs tagged with CWE-4883 Critical, 11 High, 17 Medium, 1 Low, 0 Unrated.

CVE-2026-16498

Published Jul 28, 2026

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terr…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-54497

Published Jul 17, 2026

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances retain ren…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-14621

Published Jul 4, 2026

A vulnerability has been found in FederatedAI FATE up to 2.2.0. This affects the function QueuePushReqStreamObserver.initEggroll of the file java/osx/osx-broker/src/main/java/org/…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-54311

Published Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could pollute the sandbox used…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9831

Published May 29, 2026

A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow request…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-46416

Published May 27, 2026

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared UFOWebSocketHandler instance an…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-34391

Published Mar 27, 2026

Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM comman…

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33215

Published Mar 24, 2026

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-23919

Published Mar 24, 2026

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss w…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-15576

Published Mar 9, 2026

If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may n…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-27492

Published Feb 21, 2026

Lettermint Node.js SDK is the official Node.js SDK for Lettermint. In versions 1.5.0 and below, email properties (such as to, subject, html, text, and attachments) are not reset b…

CVSS 4.7 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-23844

Published Jan 19, 2026

Whisper Money is a personal finance application. Versions prior to 0.1.5 have an insecure direct object reference vulnerability. A user can update/create account balances in other…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-23646

Published Jan 19, 2026

OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to view and end their active sessio…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-24934

Published Oct 22, 2025

Software which sets SO_REUSEPORT_LB on a socket and then connects it to a host will not directly observe any problems. However, due to its membership in a load-balancing group, t…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-47928

Published May 15, 2025

Spotipy is a Python library for the Spotify Web API. As of commit 4f5759dbfb4506c7b6280572a4db1aabc1ac778d, using `pull_request_target` on `.github/workflows/integration_tests.yml…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-30073

Published Mar 26, 2025

An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0. The reference assigned to transactions can be reused. When completing a payment, the first or all transactions…

CVSS 7.5 · High

CVE-2025-2312

Published Mar 25, 2025

A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in container…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2024-8314

Published Mar 25, 2025

An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow…

CVSS 5.5 · Medium

CVE-2025-27606

Published Mar 14, 2025

Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain circumstances, fail to logout the user if they input the w…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1247

Published Feb 13, 2025

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows…

CVSS 8.3 · High
evidence mentions
6
Buzz score
31.0

CVE-2023-1907

Published Jan 9, 2025

A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if multiple connection…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11094

Published Nov 16, 2024

The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35.17 via the export feature. This makes it possible…

CVSS 5.3 · Medium

CVE-2024-7049

Published Oct 10, 2024

In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions witho…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5148

Published Sep 2, 2024

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transi…

CVSS 7.5 · High
Showing 1-25 of 32 CVEsPage 1 of 2