Skip to main content

CWE archive

CWE-73 CVEs

Programmatic archive

514 CVEs tagged with CWE-7372 Critical, 236 High, 184 Medium, 22 Low, 0 Unrated.

CVE-2026-57916

Published Jul 27, 2026

proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local execut…

CVSS 4.6 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-65896

Published Jul 23, 2026

Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move(…

CVSS 7.1 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-14551

Published Jul 22, 2026

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privilege…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47425

Published Jul 21, 2026

Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.tr…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-15724

Published Jul 21, 2026

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrar…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-56452

Published Jul 20, 2026

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-58484

Published Jul 20, 2026

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manife…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-45139

Published Jul 20, 2026

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','jso…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-50162

Published Jul 17, 2026

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not accoun…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-9587

Published Jul 17, 2026

An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sou…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-44019

Published Jul 16, 2026

Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow lo…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-46336

Published Jul 16, 2026

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. From 0.96.0 until 0.140.0, authenticated users…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-12979

Published Jul 16, 2026

The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-15921

Published Jul 15, 2026

Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-50148

Published Jul 15, 2026

Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user w…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-61873

Published Jul 15, 2026

Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig proces…

CVSS 7.2 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-8920

Published Jul 15, 2026

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operatio…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50462

Published Jul 14, 2026

External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-55002

Published Jul 14, 2026

External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-54108

Published Jul 14, 2026

External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-15736

Published Jul 14, 2026

Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-57898

Published Jul 14, 2026

In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-61462

Published Jul 13, 2026

mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attacker…

CVSS 9.2 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-13014

Published Jul 13, 2026

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable applicat…

CVSS 9.2 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-15540

Published Jul 13, 2026

A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrati…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0
Showing 1-25 of 514 CVEsPage 1 of 21