Skip to main content

CWE archive

CWE-693 CVEs

Programmatic archive

654 CVEs tagged with CWE-69394 Critical, 231 High, 287 Medium, 42 Low, 0 Unrated.

CVE-2026-64708

Published Jul 27, 2026

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may bypass Gatekeeper che…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-28912

Published Jul 27, 2026

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-28900

Published Jul 27, 2026

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatek…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-28849

Published Jul 27, 2026

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-66391

Published Jul 27, 2026

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-48037

Published Jul 24, 2026

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silent…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-48033

Published Jul 24, 2026

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a fo…

CVSS 8.4 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-65899

Published Jul 23, 2026

DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPurify instance reused across trust boundaries stays bound to a…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-50330

Published Jul 22, 2026

An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-50329

Published Jul 22, 2026

An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2025-50327

Published Jul 22, 2026

An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection m…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-50325

Published Jul 22, 2026

BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected ins…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
23.9

CVE-2025-50324

Published Jul 22, 2026

An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-44090

Published Jul 22, 2026

An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-44089

Published Jul 22, 2026

An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-60166

Published Jul 21, 2026

Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated a…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-60164

Published Jul 21, 2026

Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated a…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-46403

Published Jul 21, 2026

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-56585

Published Jul 21, 2026

HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user acti…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-47392

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/pytho…

CVSS 9.9 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-16406

Published Jul 21, 2026

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-16394

Published Jul 21, 2026

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-16390

Published Jul 21, 2026

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 654 CVEsPage 1 of 27