Skip to main content

CWE archive

CWE-684 CVEs

Programmatic archive

27 CVEs tagged with CWE-6843 Critical, 9 High, 8 Medium, 7 Low, 0 Unrated.

CVE-2026-44597

Published May 7, 2026

Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.

CVSS 3.7 · Low
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-40685

Published Apr 30, 2026

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an inco…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-40684

Published Apr 30, 2026

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a…

CVSS 5.9 · Medium
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2026-42255

Published Apr 26, 2026

Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35381

Published Apr 22, 2026

A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) and -d '' (empty delimiter) opti…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-35379

Published Apr 22, 2026

A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The implementation mistakenly includes…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-34478

Published Apr 10, 2026

Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via C…

CVSS 6.9 · Medium
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2025-66384

Published Nov 28, 2025

app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, related to tmp_name.

CVSS 8.2 · High

CVE-2025-55174

Published Nov 26, 2025

In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning followed by the partial contents of the old file at the en…

CVSS 3.2 · Low

CVE-2025-58325

Published Oct 14, 2025

An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through 7.0.15, 6.4 all versions may a…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54568

Published Jul 25, 2025

Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separately for each edge node.

CVSS 3.7 · Low

CVE-2025-54567

Published Jul 25, 2025

hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47227

Published Jul 5, 2025

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is mishandled. Making both a GET and a POST request…

CVSS 7.5 · High

CVE-2024-50357

Published Nov 29, 2024

FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs…

CVSS 9.8 · Critical

CVE-2024-5005

Published Oct 11, 2024

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starti…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-8974

Published Sep 26, 2024

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to d…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-20317

Published Sep 11, 2024

A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an unauthenticated, a…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6502

Published Aug 22, 2024

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6425

Published Jul 1, 2024

Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authentica…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-4258

Published Sep 25, 2023

In Bluetooth mesh implementation If provisionee has a public key that is sent OOB then during provisioning it can be sent back and will be accepted by provisionee.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5158

Published Sep 25, 2023

A flaw was found in vringh_kiov_advance in drivers/vhost/vringh.c in the host side of a virtio ring in the Linux Kernel. This issue may result in a denial of service from guest to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2