Skip to main content

CWE archive

CWE-489 CVEs

Programmatic archive

85 CVEs tagged with CWE-48915 Critical, 44 High, 22 Medium, 4 Low, 0 Unrated.

CVE-2026-65893

Published Jul 27, 2026

This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-58378

Published Jul 9, 2026

Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim a…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54799

Published Jul 9, 2026

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application cont…

CVSS 8.4 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54798

Published Jul 9, 2026

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application incl…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-58191

Published Jul 8, 2026

Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-59092

Published Jul 2, 2026

JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics…

CVSS 7.0 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-45728

Published May 26, 2026

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9133

Published May 20, 2026

Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate vali…

CVSS 8.3 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-40035

Published Apr 8, 2026

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a s…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-32662

Published Apr 3, 2026

Development and test API endpoints are present that mirror production functionality.

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-33201

Published Mar 26, 2026

Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vulnerability is exploited, files or configurations on the aff…

CVSS 7.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-27131

Published Mar 23, 2026

The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.2, admin users, and users with…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2025-15017

Published Dec 31, 2025

A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical access to the device can directly connect…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-42872

Published Dec 9, 2025

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of oth…

CVSS 6.1 · Medium

CVE-2025-2486

Published Nov 26, 2025

The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Version…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-64983

Published Nov 26, 2025

Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attacker to connect via Telnet and gain access to the device.

CVSS 8.6 · High

CVE-2025-54660

Published Nov 18, 2025

An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.0 all versions may allow a loc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30185

Published Nov 11, 2025

Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escalation of privilege. System software adversary with a privile…

CVSS 8.3 · High

CVE-2025-52663

Published Oct 31, 2025

A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with acces…

CVSS 7.3 · High

CVE-2025-4106

Published Oct 24, 2025

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and versio…

CVSS 8.9 · High

CVE-2025-36899

Published Sep 4, 2025

There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to physical escalation of privilege with no additional execution…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-7705

Published Jul 22, 2025

: Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU -83330-500.This issue affects Switch Actuator 4 DU-83330: All Versions; S…

CVSS 8.6 · High

CVE-2025-1479

Published May 30, 2025

An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code.

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 85 CVEsPage 1 of 4