Skip to main content

CWE archive

CWE-646 CVEs

Programmatic archive

10 CVEs tagged with CWE-6461 Critical, 3 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2026-45315

Published May 15, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload endpoint takes the file extension…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-20172

Published May 6, 2026

A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To exploit this…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-41720

Published Oct 22, 2025

A low privileged remote attacker can upload arbitrary data masked as a png file to the affected device using the webserver API because only the file extension is verified.

CVSS 4.3 · Medium

CVE-2025-58449

Published Sep 8, 2025

Maho is a free and open source ecommerce platform. In Maho prior to 25.9.0, an authenticated staff user with access to the `Dashboard` and `Catalog\Manage Products` permissions ca…

CVSS 8.7 · High

CVE-2025-1889

Published Mar 3, 2025

picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and inc…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-45599

Published Mar 5, 2024

A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attac…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34639

Published Aug 5, 2021

Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is exe…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1