Skip to main content

CWE archive

CWE-538 CVEs

Programmatic archive

93 CVEs tagged with CWE-5383 Critical, 28 High, 57 Medium, 5 Low, 0 Unrated.

CVE-2026-15574

Published Jul 13, 2026

A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain perso…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-50099

Published Jun 12, 2026

During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The U…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-50565

Published Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission buil…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-46617

Published Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, Fission runt…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-29114

Published Jun 10, 2026

A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the attacker…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-10254

Published Jun 1, 2026

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory info…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-49298

Published Jun 1, 2026

A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line a…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-5434

Published May 21, 2026

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing syste…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-27173

Published May 19, 2026

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only acc…

CVSS 8.7 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2023-54346

Published May 5, 2026

WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated attackers to download complete database backups by accessing p…

CVSS 8.7 · High

CVE-2026-7071

Published Apr 27, 2026

A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The manipul…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-6160

Published Apr 13, 2026

A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performi…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2019-25706

Published Apr 12, 2026

Across DR-810 contains an unauthenticated file disclosure vulnerability that allows remote attackers to download the rom-0 backup file containing sensitive information by sending…

CVSS 8.7 · High

CVE-2026-33705

Published Apr 10, 2026

Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-52642

Published Mar 16, 2026

HCL AION is affected by a vulnerability where internal filesystem paths may be exposed through application responses or system behaviour. Exposure of internal paths may reveal env…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-20024

Published Mar 16, 2026

ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can ex…

CVSS 9.3 · Critical

CVE-2026-21672

Published Mar 12, 2026

A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

CVSS 8.8 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-2817

Published Feb 19, 2026

Use of insecure directory in Spring Data Geode snapshot import extracts archives into predictable, permissive directories under the system temp location. On shared hosts, a local…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2020-37104

Published Feb 11, 2026

ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attack…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-12059

Published Feb 11, 2026

Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platform allows Exploiting Incorrectl…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-12699

Published Feb 10, 2026

The ZOLL ePCR IOS application reflects unsanitized user input into a WebView. Attacker-controlled strings placed into PCR fields (run number, incident, call sign, notes) are inter…

CVSS 6.7 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2025-36058

Published Jan 20, 2026

IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 93 CVEsPage 1 of 4