Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,612 CVEs tagged with CWE-5947 Critical, 710 High, 673 Medium, 182 Low, 0 Unrated.

CVE-2026-54706

Published Jul 31, 2026

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/De…

CVSS 4.8 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-67433

Published Jul 29, 2026

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-13268

Published Jul 29, 2026

G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installa…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-13723

Published Jul 29, 2026

A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-43765

Published Jul 27, 2026

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to modify prote…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-17459

Published Jul 26, 2026

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/Extern…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-12503

Published Jul 24, 2026

Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `lar…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-65069

Published Jul 21, 2026

Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h with o…

CVSS 4.0 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-65068

Published Jul 21, 2026

Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h wit…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65067

Published Jul 21, 2026

Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h with ope…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65066

Published Jul 21, 2026

Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h with o…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65065

Published Jul 21, 2026

Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roaring.h…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-65064

Published Jul 21, 2026

Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_generic.h wi…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65063

Published Jul 21, 2026

Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h with o…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65062

Published Jul 21, 2026

Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sortedset.h wi…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-65061

Published Jul 21, 2026

Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in reqrep.h with ope…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-64617

Published Jul 21, 2026

Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h with ope…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-64616

Published Jul 21, 2026

Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ndarray.h with o…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-64615

Published Jul 21, 2026

Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in graph.h with open(…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-64614

Published Jul 21, 2026

Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h with open(…

CVSS 3.8 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-64613

Published Jul 21, 2026

Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created in buf_generic.h with open(pat…

CVSS 6.2 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-47121

Published Jul 21, 2026

Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-15788

Published Jul 20, 2026

BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by a…

CVSS 5.6 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-8170

Published Jul 20, 2026

The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privil…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-58414

Published Jul 20, 2026

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_col…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9
Showing 1-25 of 1,612 CVEsPage 1 of 65