Skip to main content

CWE archive

CWE-494 CVEs

Programmatic archive

211 CVEs tagged with CWE-49437 Critical, 125 High, 41 Medium, 8 Low, 0 Unrated.

CVE-2026-66398

Published Jul 27, 2026

phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-50562

Published Jul 15, 2026

FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/w…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2021-47987

Published Jun 25, 2026

Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork o…

CVSS 7.7 · High

CVE-2021-47986

Published Jun 25, 2026

Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attacker…

CVSS 7.7 · High

CVE-2026-55698

Published Jun 25, 2026

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55697

Published Jun 25, 2026

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9037

Published May 28, 2026

A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Becaus…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45058

Published May 28, 2026

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-9089

Published May 21, 2026

The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This issue is addressed in Automate…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42575

Published May 9, 2026

apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifies the signature on APKINDEX.tar.gz but never compares indi…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-32148

Published Apr 30, 2026

Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex s…

CVSS 8.9 · High
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-42249

Published Apr 29, 2026

Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading u…

CVSS 7.7 · High
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-42248

Published Apr 29, 2026

Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verif…

CVSS 7.7 · High
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2025-10539

Published Apr 28, 2026

Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client a…

CVSS 4.8 · Medium
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2026-3428

Published Apr 16, 2026

A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Administrator via…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-34841

Published Apr 6, 2026

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, wh…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-30603

Published Apr 2, 2026

An issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access, install backdoors, and exfiltrate data via supplying a craf…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-3502

Published Mar 30, 2026

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a ta…

CVSS 7.8 · High
evidence mentions
8
Buzz score
67.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-33075

Published Mar 20, 2026

FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28500

Published Mar 18, 2026

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub…

CVSS 8.6 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-1878

Published Mar 12, 2026

An Insufficient Integrity Verification vulnerability in the ASUS ROG peripheral driver installation process allows privilege escalation to SYSTEM. The vulnerability is due to impr…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-3000

Published Mar 2, 2026

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary D…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-2999

Published Mar 2, 2026

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary e…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 211 CVEsPage 1 of 9