Skip to main content

CWE archive

CWE-669 CVEs

Programmatic archive

98 CVEs tagged with CWE-66910 Critical, 34 High, 42 Medium, 12 Low, 0 Unrated.

CVE-2026-14151

Published Jun 30, 2026

Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox esca…

CVSS 8.3 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-46448

Published Jun 16, 2026

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-12068

Published Jun 12, 2026

Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials aut…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44917

Published Jun 4, 2026

OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-46447

Published Jun 3, 2026

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

CVSS 5.8 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-48847

Published May 25, 2026

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

CVSS 3.7 · Low
evidence mentions
5
Buzz score
27.9

CVE-2026-48846

Published May 25, 2026

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may le…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-48845

Published May 25, 2026

In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-48831

Published May 24, 2026

Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file c…

CVSS 7.3 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-44599

Published May 7, 2026

Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.

CVSS 3.7 · Low
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-42997

Published May 5, 2026

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential…

CVSS 7.7 · High
evidence mentions
7
Buzz score
35.3
Vendor/product tagsBeta · best-effort

CVE-2026-40552

Published Apr 28, 2026

mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command executi…

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-41525

Published Apr 28, 2026

KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin'…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
32.6

CVE-2026-41030

Published Apr 16, 2026

In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges.

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-40228

Published Apr 10, 2026

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

CVSS 2.9 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40225

Published Apr 10, 2026

In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-35545

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to inf…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-35544

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-35543

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail mes…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-35542

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-35540

Published Apr 3, 2026

An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Di…

CVSS 5.4 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2025-41660

Published Mar 24, 2026

A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.

CVSS 8.8 · High

CVE-2026-33265

Published Mar 18, 2026

In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-32772

Published Mar 16, 2026

telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.

CVSS 3.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 98 CVEsPage 1 of 4