Skip to main content

CWE archive

CWE-647 CVEs

Programmatic archive

10 CVEs tagged with CWE-6470 Critical, 4 High, 4 Medium, 2 Low, 0 Unrated.

CVE-2026-62685

Published Jul 15, 2026

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-8384

Published Jul 14, 2026

In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the exp…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-59731

Published Jul 8, 2026

Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially decoded pathname after reaching the iterative URL decoder limit…

CVSS 8.2 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-5222

Published May 25, 2026

Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be host…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2025-66202

Published Dec 9, 2025

Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based authentication checks in Astro…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47241

Published May 3, 2025

In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component.

CVSS 4.0 · Medium

CVE-2025-43916

Published Apr 21, 2025

Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authority component, which is not consistent w…

CVSS 3.4 · Low

CVE-2022-43939

Published Apr 3, 2023

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumve…

CVSS 8.6 · High
evidence mentions
3
Buzz score
50.4
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1