Skip to main content

CWE archive

CWE-693 CVEs

Programmatic archive

657 CVEs tagged with CWE-69394 Critical, 233 High, 288 Medium, 42 Low, 0 Unrated.

CVE-2026-17919

Published Jul 30, 2026

Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via physical access to the de…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-17899

Published Jul 30, 2026

Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-67427

Published Jul 29, 2026

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variab…

CVSS 8.6 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-64708

Published Jul 27, 2026

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may bypass Gatekeeper che…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-28912

Published Jul 27, 2026

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.

CVSS 7.8 · High
evidence mentions
3
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-28900

Published Jul 27, 2026

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatek…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-28849

Published Jul 27, 2026

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-66391

Published Jul 27, 2026

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-48037

Published Jul 24, 2026

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silent…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-48033

Published Jul 24, 2026

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a fo…

CVSS 8.4 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-65899

Published Jul 23, 2026

DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-50330

Published Jul 22, 2026

An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-50329

Published Jul 22, 2026

An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2025-50327

Published Jul 22, 2026

An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection m…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-50325

Published Jul 22, 2026

BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected ins…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2025-50324

Published Jul 22, 2026

An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-44090

Published Jul 22, 2026

An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-44089

Published Jul 22, 2026

An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-60166

Published Jul 21, 2026

Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated a…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-60164

Published Jul 21, 2026

Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated a…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-46403

Published Jul 21, 2026

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-56585

Published Jul 21, 2026

HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user acti…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47392

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/pytho…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
18.9
Showing 1-25 of 657 CVEsPage 1 of 27