Skip to main content

CWE archive

CWE-704 CVEs

Programmatic archive

273 CVEs tagged with CWE-70423 Critical, 198 High, 47 Medium, 5 Low, 0 Unrated.

CVE-2025-51678

Published Jul 17, 2026

An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior.

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-50337

Published Jul 14, 2026

Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-59871

Published Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing d…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-55076

Published Jul 7, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_v…

CVSS 7.4 · High
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-48140

Published Jun 19, 2026

There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigger invalid enum states and undefined behavior, potentially r…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-46690

Published Jun 12, 2026

unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/R…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45685

Published Jun 2, 2026

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages c…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-44324

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/a…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-46597

Published May 22, 2026

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

CVSS 7.5 · High
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2023-7345

Published May 19, 2026

Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messag…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-44223

Published May 12, 2026

vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a t…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-42576

Published May 9, 2026

apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKeys in pkg/apk/apk/implementation.go unconditionally type-ass…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-40613

Published Apr 21, 2026

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing functions in coturn perform unsafe pointer casts from uint8_t…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34379

Published Apr 6, 2026

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9,…

CVSS 7.1 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2021-4456

Published Feb 27, 2026

Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions `addr2cidr` and `cidrlookup` may return lea…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-40541

Published Feb 24, 2026

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort

CVE-2025-40540

Published Feb 24, 2026

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requi…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort

CVE-2025-40539

Published Feb 24, 2026

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requi…

CVSS 9.1 · Critical
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort

CVE-2026-25613

Published Feb 10, 2026

An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compound wildcard index.

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25518

Published Feb 4, 2026

cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. In…

CVSS 5.9 · Medium
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2026-25503

Published Feb 3, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, type confusi…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-24856

Published Jan 28, 2026

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Versions prior to 2.3.1.2 have an unde…

CVSS 7.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-71002

Published Jan 28, 2026

A floating-point exception (FPE) in the flow.column_stack component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12781

Published Jan 21, 2026

When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the…

CVSS 6.3 · Medium
evidence mentions
8
Buzz score
36.5
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 273 CVEsPage 1 of 11