Skip to main content

CWE archive

CWE-697 CVEs

Programmatic archive

160 CVEs tagged with CWE-69716 Critical, 63 High, 71 Medium, 10 Low, 0 Unrated.

CVE-2026-48032

Published Jul 24, 2026

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypass…

CVSS 8.3 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-65903

Published Jul 23, 2026

DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden tags to bypass FORBID_TAGS restrictions. Attackers can craft…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-55771

Published Jul 13, 2026

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equal…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-22660

Published Jul 10, 2026

FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administrators to delete all built-in authorization groups by exploit…

CVSS 8.6 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-59890

Published Jul 8, 2026

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclud…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-14687

Published Jul 5, 2026

A vulnerability was determined in 666ghj BettaFish up to 1.2.1. Impacted is the function _deduplicate_results of the file InsightEngine/agent.py of the component InsightEngine sea…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-14686

Published Jul 5, 2026

A vulnerability was found in HdrHistogram up to 2.2.2. This issue affects the function org.HdrHistogram.DoubleHistogram.recordValue of the file src/main/java/org/HdrHistogram/Doub…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-14617

Published Jul 3, 2026

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/…

CVSS 1.3 · Low
evidence mentions
8
Buzz score
30.0

CVE-2026-10097

Published Jun 25, 2026

wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes during the Fujisaki-Okamoto re-encryption check in ML-KEM-1024 deca…

CVSS 8.3 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-49340

Published Jun 19, 2026

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePlaylist` allows any authentica…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44249

Published Jun 11, 2026

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass…

CVSS 8.1 · High
evidence mentions
14
Buzz score
40.1
Vendor/product tagsBeta · best-effort

CVE-2026-45569

Published Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-45567

Published Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' sub…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47202

Published May 26, 2026

Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user incl…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-9369

Published May 24, 2026

A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the compon…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-44196

Published May 12, 2026

Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-35040

Published Apr 9, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in the allowedAud, allowedIss, allowedSub, allowedJti, or all…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-34574

Published Mar 31, 2026

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypa…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-34210

Published Mar 31, 2026

mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Replayed response header…

CVSS 6.0 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-32322

Published Mar 13, 2026

soroban-sdk is a Rust SDK for Soroban contracts. Prior to 22.0.11, 23.5.3, and 25.3.0, The Fr (scalar field) types for BN254 and BLS12-381 in soroban-sdk compared values using the…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26275

Published Feb 19, 2026

httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to version 0.0.23 where Digest header verification could incorrect…

CVSS 7.5 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-21691

Published Jan 7, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versi…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-20343

Published Nov 5, 2025

A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote att…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-12192

Published Nov 5, 2025

The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.9. The sysinfo REST endpoint compares the provided key to t…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-47416

Published Sep 9, 2025

A vulnerability exists in the ConsoleFindCommandMatchList function in libsymproc. so imported by ctpd that may lead to unauthorized execution of an attacker-defined file that gets…

CVSS 5.9 · Medium
Showing 1-25 of 160 CVEsPage 1 of 7