Skip to main content

CWE archive

CWE-670 CVEs

Programmatic archive

142 CVEs tagged with CWE-67010 Critical, 63 High, 56 Medium, 13 Low, 0 Unrated.

CVE-2026-16392

Published Jul 21, 2026

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-14935

Published Jul 7, 2026

A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP off…

CVSS 3.7 · Low
evidence mentions
4
Buzz score
27.6

CVE-2026-56328

Published Jun 30, 2026

Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unnamed /updates requests without defaultChannel implicitly re…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-7656

Published Jun 29, 2026

The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 486…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-55276

Published Jun 29, 2026

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.x…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-53404

Published Jun 29, 2026

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-56307

Published Jun 20, 2026

Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to ca…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-48844

Published May 25, 2026

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code…

CVSS 7.5 · High
evidence mentions
5
Buzz score
27.9

CVE-2026-20171

Published May 20, 2026

A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-O…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-38361

Published May 8, 2026

Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_uploader/httprequesthandler.py, dash_up…

CVSS 7.5 · High
evidence mentions
11
Buzz score
49.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44928

Published May 8, 2026

In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.

CVSS 2.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41988

Published Apr 23, 2026

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used…

CVSS 3.2 · Low
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-35343

Published Apr 22, 2026

The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to verify t…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-41527

Published Apr 21, 2026

KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there is an error in the mechanism (KUniqueService) for ensuring t…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-40942

Published Apr 21, 2026

The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Document caches us…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-6608

Published Apr 20, 2026

A vulnerability was detected in lm-sys fastchat up to 0.2.36. Impacted is the function add_text of the component Arena Side-by-Side View Handler. The manipulation results in incor…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-40960

Published Apr 16, 2026

Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-40719

Published Apr 15, 2026

Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolved.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-40396

Published Apr 12, 2026

Varnish Cache 9 before 9.0.1 allows a "workspace overflow" denial of service (daemon panic) after timeout_linger. A malicious client could send an HTTP/1 request, wait long enough…

CVSS 4.0 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-40200

Published Apr 10, 2026

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word pr…

CVSS 8.1 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-34946

Published Apr 9, 2026

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a vulnerability where the compilation of the table.fill…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35414

Published Apr 2, 2026

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certa…

CVSS 4.2 · Medium
evidence mentions
6
Buzz score
39.5
Vendor/product tagsBeta · best-effort

CVE-2026-35387

Published Apr 2, 2026

OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all EC…

CVSS 3.1 · Low
evidence mentions
5
Buzz score
37.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 142 CVEsPage 1 of 6