Skip to main content

CWE archive

CWE-665 CVEs

Programmatic archive

354 CVEs tagged with CWE-66520 Critical, 137 High, 166 Medium, 31 Low, 0 Unrated.

CVE-2026-62433

Published Jul 28, 2026

Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation without any checking being done. As a result, certain oper…

CVSS 7.3 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-44434

Published Jul 16, 2026

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless reset injection t…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-54777

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-54409

Published Jul 2, 2026

A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authe…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54279

Published Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later wit…

CVSS 1.3 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-12539

Published Jun 18, 2026

Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon r…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-35991

Published May 12, 2026

Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information disclosure. System software adversary with a privileged…

CVSS 5.6 · Medium

CVE-2026-34553

Published Mar 31, 2026

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a defect in LUT dump/iteration logic affecting CIcc…

CVSS 4.0 · Medium
evidence mentions
3
Buzz score
23.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-0940

Published Mar 11, 2026

A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local privileged user to modify data and execute arbitrary code.

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-26958

Published Feb 19, 2026

filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographic primitives. In versions 1.1.0 and earlier, MultiScalarMul…

CVSS 1.7 · Low
evidence mentions
3
Buzz score
18.9

CVE-2025-48509

Published Feb 10, 2026

Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause misidentification of I/O memory, potentially resulting in a…

CVSS 1.8 · Low

CVE-2025-25058

Published Feb 10, 2026

Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Driv…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-23553

Published Jan 28, 2026

In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the previous vCPU to run. While safe for Xen's isolation between…

CVSS 2.9 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-14955

Published Dec 19, 2025

A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component PFCP…

CVSS 2.9 · Low
evidence mentions
8
Buzz score
33.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-12902

Published Nov 7, 2025

Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical access to gain un-authorized access to a locked Storage Device o…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-36331

Published Sep 6, 2025

Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SNP guest memory resulting in loss of data integrity.

CVSS 3.2 · Low

CVE-2025-24511

Published Aug 12, 2025

Improper initialization in the Linux kernel-mode driver for some Intel(R) I350 Series Ethernet before version 5.19.2 may allow an authenticated user to potentially enable Informat…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2025-22834

Published Aug 12, 2025

AMI APTIOV contains a vulnerability in BIOS where a user may cause “Improper Initialization” by local accessing. Successful exploitation of this vulnerability may leave the resour…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-5745

Published Jun 5, 2025

The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 to v31 without saving contents from the c…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5702

Published Jun 5, 2025

The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the ca…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21100

Published May 13, 2025

Improper initialization in the UEFI firmware for the Intel(R) Server D50DNP and M50FCP boards may allow a privileged user to potentially enable information disclosure via local ac…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 354 CVEsPage 1 of 15