Skip to main content

CWE archive

CWE-664 CVEs

Programmatic archive

43 CVEs tagged with CWE-6641 Critical, 17 High, 23 Medium, 2 Low, 0 Unrated.

CVE-2026-20158

Published Jul 15, 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This rev…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-43503

Published May 23, 2026

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through frag-transfer helpers Two frag-transfer helpers (__pskb_cop…

CVSS 8.8 · High
evidence mentions
45
Buzz score
54.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-8582

Published May 14, 2026

Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTM…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-8517

Published May 14, 2026

Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbi…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-34226

Published Oct 3, 2025

OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be craft…

CVSS 7.1 · High

CVE-2025-54621

Published Aug 6, 2025

Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory release failures.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54619

Published Aug 6, 2025

Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause iterator failures and affect availability.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54613

Published Aug 6, 2025

Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54612

Published Aug 6, 2025

Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41169

Published Jul 12, 2025

The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Z…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-21593

Published Jan 9, 2025

An Improper Control of a Resource Through its Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticat…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-7889

Published Sep 11, 2024

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37139

Published Jun 26, 2024

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a Resource Through its Lifetime vulnerability in an admin ope…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36774

Published Feb 19, 2024

plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23639

Published Feb 9, 2024

Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the Groovy…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22365

Published Feb 6, 2024

linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44295

Published Dec 5, 2023

Dell PowerScale OneFS versions 8.2.2.x through 9.6.0.x contains an improper control of a resource through its lifetime vulnerability. A low privilege attacker could potentially ex…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44288

Published Dec 5, 2023

Dell PowerScale OneFS, 8.2.2.x through 9.6.0.x, contains an improper control of a resource through its lifetime vulnerability. An unauthenticated network attacker could potentiall…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25942

Published Apr 4, 2023

Dell PowerScale OneFS versions 8.2.x-9.4.x contain an uncontrolled resource consumption vulnerability. A malicious network user with low privileges could potentially exploit this…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32846

Published Feb 27, 2023

A logic issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28287

Published Dec 22, 2022

In unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. This vulnerability affects Firefox < 99.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 43 CVEsPage 1 of 2