Skip to main content

CWE archive

CWE-698 CVEs

Programmatic archive

17 CVEs tagged with CWE-6983 Critical, 9 High, 2 Medium, 3 Low, 0 Unrated.

CVE-2026-58455

Published Jul 2, 2026

Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing e…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-10271

Published Jun 1, 2026

A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected element is an unknown function of the file admin/ of the compo…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-2699

Published Apr 2, 2026

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration…

CVSS 9.8 · Critical
evidence mentions
6
Buzz score
39.5
Vendor/product tagsBeta · best-effort

CVE-2026-3264

Published Feb 26, 2026

A vulnerability was determined in go2ismail Free-CRM up to b83c40a90726d5e58f0cc680ffdcaa28a03fb5d1. Affected by this issue is some unknown functionality of the component Administ…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-8350

Published Feb 19, 2026

Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HT…

CVSS 9.8 · Critical

CVE-2025-6967

Published Feb 10, 2026

Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Auth…

CVSS 8.7 · High

CVE-2024-48766

Published May 13, 2025

NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversa…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2635

Published Mar 19, 2024

The configuration pages available are not intended to be placed on an Internet facing web server, as they expose file paths to the client, who can be an attacker. Instead of rewri…

CVSS 7.3 · High

CVE-2024-2573

Published Mar 18, 2024

A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file /task-info.php. The manipu…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2572

Published Mar 18, 2024

A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /task-detail…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2571

Published Mar 18, 2024

A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage-admi…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2570

Published Mar 18, 2024

A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file /edit-task.php. The m…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2569

Published Mar 18, 2024

A vulnerability was found in SourceCodester Employee Task Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1