Skip to main content

CWE archive

CWE-693 CVEs

Programmatic archive

636 CVEs tagged with CWE-69393 Critical, 224 High, 279 Medium, 40 Low, 0 Unrated.

CVE-2026-1232

Published Feb 2, 2026

A medium-severity vulnerability has been identified in BeyondTrust Privilege Management for Windows versions <=25.7. Under certain conditions, a local authenticated user with elev…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-23553

Published Jan 28, 2026

In the context switch logic Xen attempts to skip an IBPB in the case of a vCPU returning to a CPU on which it was the previous vCPU to run. While safe for Xen's isolation between…

CVSS 2.9 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-40536

Published Jan 28, 2026

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certai…

CVSS 8.1 · High
evidence mentions
12
Buzz score
70.2
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-23830

Published Jan 28, 2026

SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. The libr…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-24868

Published Jan 27, 2026

Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-22709

Published Jan 26, 2026

vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization can be bypassed. This allows…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2025-55249

Published Jan 19, 2026

HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and incre…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2026-22686

Published Jan 14, 2026

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrus…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-0877

Published Jan 13, 2026

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVSS 8.1 · High
evidence mentions
32
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2025-69264

Published Jan 7, 2026

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Depen…

CVSS 8.8 · High
evidence mentions
6
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2025-15422

Published Jan 2, 2026

A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. This manipulat…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68668

Published Dec 26, 2025

n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authent…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-46291

Published Dec 17, 2025

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may bypass Gatekeeper checks.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46281

Published Dec 17, 2025

A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.2. An app may be able to break out of its sandbox.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13326

Published Dec 17, 2025

Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC pe…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-14095

Published Dec 17, 2025

A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of this vulnerability gives a user with physical access to the an…

CVSS 6.8 · Medium

CVE-2025-14304

Published Dec 17, 2025

Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly ena…

CVSS 7.0 · High
evidence mentions
2
Buzz score
17.5

CVE-2025-14303

Published Dec 17, 2025

Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a…

CVSS 7.0 · High
evidence mentions
2
Buzz score
17.5

CVE-2025-14302

Published Dec 17, 2025

Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can u…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-65319

Published Dec 16, 2025

When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-65318

Published Dec 16, 2025

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-36938

Published Dec 11, 2025

In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalation of privilege with no additional execu…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 636 CVEsPage 11 of 26