Skip to main content

CWE archive

CWE-641 CVEs

Programmatic archive

16 CVEs tagged with CWE-6410 Critical, 11 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-50510

Published Jul 14, 2026

Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-50023

Published Jun 23, 2026

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-27140

Published Apr 8, 2026

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

CVSS 8.8 · High
evidence mentions
22
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2019-25623

Published Mar 23, 2026

Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface.…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47260

Published Mar 4, 2025

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient input validation allowing for uploading more audio clips th…

CVSS 6.5 · Medium

CVE-2024-45312

Published Sep 2, 2024

Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a vulnerability that all…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0046

Published Jan 4, 2023

Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23536

Published Dec 19, 2022

Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36302

Published Aug 1, 2022

File path manipulation vulnerability in BF-OS version 3.00 up to and including 3.83 allows an attacker to modify the file path to access different resources, which may contain sen…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41146

Published Oct 21, 2021

qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` UR…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1