Skip to main content

CWE archive

CWE-707 CVEs

Programmatic archive

252 CVEs tagged with CWE-7072 Critical, 17 High, 106 Medium, 127 Low, 0 Unrated.

CVE-2026-11457

Published Jun 7, 2026

A security flaw has been discovered in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This vulnerability affects unknown code of the file /base-boot/jmreport/te…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-10661

Published Jun 2, 2026

A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the function Open of the file src/blender_mcp/server.py. The man…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-10223

Published Jun 1, 2026

A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. This affects the function _scan_memory_content of the file tools/memory_tool.py. This manipulation cau…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-10222

Published Jun 1, 2026

A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-10221

Published Jun 1, 2026

A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulati…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-10220

Published Jun 1, 2026

A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_tool.py. Executing a…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-10210

Published Jun 1, 2026

A vulnerability was found in AstrBotDevs AstrBot 4.23.6. Affected by this vulnerability is the function _sanitize_prompt_description of the file astrbot/core/skills/skill_manager.…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-9422

Published May 25, 2026

A vulnerability was identified in KLiK SocialMediaWebsite 1.0. This issue affects some unknown processing of the component HTTP POST Request Parameter Handler. Such manipulation l…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-9420

Published May 25, 2026

A vulnerability was found in KLiK SocialMediaWebsite 1.0. This affects an unknown part of the component HTTP GET Request Parameter Handler. The manipulation results in injection.…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
24.5

CVE-2026-9366

Published May 24, 2026

A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-9353

Published May 24, 2026

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of the component Skills…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-7045

Published Apr 26, 2026

A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dyn…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-6994

Published Apr 25, 2026

A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the comp…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-6599

Published Apr 20, 2026

A vulnerability was detected in langflow-ai langflow up to 1.8.3. The impacted element is the function get_client_ip/install_mcp_config of the file src/backend/base/langflow/api/v…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-5561

Published Apr 5, 2026

A vulnerability was determined in Campcodes Complete POS Management and Inventory System up to 4.0.6. This affects an unknown function of the file app/Http/Controllers/SettingsCon…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-5002

Published Mar 28, 2026

A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The impacted element is the function _route_using_overviews of the file ba…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-4516

Published Mar 21, 2026

A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. This vulnerability affects unknown code of the file metagpt/actions/di/write_analysis_code.py of the component…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-4511

Published Mar 21, 2026

A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src/vanna/legacy. Such manipulation leads to injection. The at…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-4500

Published Mar 20, 2026

A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the file backend/app/ai/code_execution/code_execution.py. Such man…

CVSS 2.1 · Low
evidence mentions
9
Buzz score
29.5

CVE-2026-3992

Published Mar 12, 2026

A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. This affects an unknown part of the file utils/dynamodb.ts of the component Users Endpoint. This ma…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-3813

Published Mar 9, 2026

A vulnerability was identified in opencc JFlow up to 5badc00db382d7cb82dad231e6a866b18e0addfe. Affected by this vulnerability is the function Calculate of the file src/main/java/b…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-2954

Published Feb 22, 2026

A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataControl…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-14674

Published Dec 14, 2025

A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2025-66545

Published Dec 5, 2025

Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user wit…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 252 CVEsPage 1 of 11