Skip to main content

CWE archive

CWE-662 CVEs

Programmatic archive

60 CVEs tagged with CWE-6622 Critical, 25 High, 29 Medium, 4 Low, 0 Unrated.

CVE-2026-13489

Published Jun 28, 2026

A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of the file main/mcp_server.cc of the component MCP Response Ha…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-53277

Published Jun 25, 2026

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation walk_s1() and kvm_wal…

CVSS 8.8 · High
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-39865

Published Apr 8, 2026

Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bu…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-28789

Published Mar 5, 2026

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-22853

Published Aug 12, 2025

Improper synchronization in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS 1.8 · Low
evidence mentions
1
Buzz score
11.9

CVE-2024-58131

Published Apr 6, 2025

FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a malicious node (that has modified the codebase to allow a lar…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27104

Published Feb 21, 2025

vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the iterator target of a for loop. While the iterator expression…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-7409

Published Aug 5, 2024

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket…

CVSS 7.5 · High

CVE-2024-32644

Published Apr 19, 2024

Evmos is a scalable, high-throughput Proof-of-Stake EVM blockchain that is fully compatible and interoperable with Ethereum. Prior to 17.0.0, there is a way to mint arbitrary toke…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-46939

Published Feb 27, 2024

In the Linux kernel, the following vulnerability has been resolved: tracing: Restructure trace_clock_global() to never block It was reported that a fix to the ring buffer recurs…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45084

Published Dec 5, 2023

An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5088

Published Nov 3, 2023

A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). Th…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2801

Published Jun 6, 2023

Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such que…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32648

Published Jan 3, 2023

In disp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is…

CVSS 6.4 · Medium

CVE-2022-32645

Published Jan 3, 2023

In vow, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interacti…

CVSS 4.1 · Medium

CVE-2022-32644

Published Jan 3, 2023

In vow, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is n…

CVSS 6.4 · Medium
Showing 1-25 of 60 CVEsPage 1 of 3