Skip to main content

CWE archive

CWE-551 CVEs

Programmatic archive

23 CVEs tagged with CWE-5513 Critical, 17 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-13676

Published Jun 29, 2026

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on th…

CVSS 7.5 · High
evidence mentions
17
Buzz score
43.4
Vendor/product tagsBeta · best-effort

CVE-2026-57920

Published Jun 26, 2026

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50559

Published Jun 19, 2026

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based aut…

CVSS 7.5 · High
evidence mentions
10
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2026-45832

Published Jun 12, 2026

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization control…

CVSS 8.8 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-44575

Published May 13, 2026

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based che…

CVSS 7.5 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-44574

Published May 13, 2026

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can…

CVSS 8.1 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-44573

Published May 13, 2026

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middl…

CVSS 7.5 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-39852

Published May 5, 2026

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsist…

CVSS 8.8 · High
evidence mentions
10
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2026-40022

Published Apr 27, 2026

When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin…

CVSS 8.2 · High
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-22754

Published Apr 22, 2026

Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern="/endpoint/**"/> to define the servlet path for computing a…

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-28808

Published Apr 7, 2026

Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When s…

CVSS 8.3 · High
evidence mentions
10
Buzz score
44.0
Vendor/product tagsBeta · best-effort

CVE-2026-4636

Published Apr 2, 2026

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resour…

CVSS 8.1 · High
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2026-33186

Published Mar 20, 2026

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-head…

CVSS 9.1 · Critical
evidence mentions
201
Buzz score
48.0
Vendor/product tagsBeta · best-effort

CVE-2016-20030

Published Mar 16, 2026

ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by submitting partial characters via the usern…

CVSS 9.3 · Critical

CVE-2026-2293

Published Feb 27, 2026

A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue…

CVSS 8.2 · High
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-0707

Published Jan 8, 2026

A flaw was found in Keycloak. The Keycloak Authorization header parser is overly permissive regarding the formatting of the "Bearer" authentication scheme. It accepts non-standard…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2023-23924

Published Feb 1, 2023

Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-32779

Published Aug 24, 2021

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions envoy incorrectly handled a URI '#fragment' e…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32777

Published Aug 24, 2021

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. In affected versions when ext-authz extension is sending request h…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1