Skip to main content

CWE archive

CWE-749 CVEs

Programmatic archive

177 CVEs tagged with CWE-74945 Critical, 81 High, 50 Medium, 1 Low, 0 Unrated.

CVE-2026-45805

Published Jul 15, 2026

Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 an…

CVSS 8.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-53633

Published Jul 14, 2026

Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
29.0

CVE-2025-53827

Published Jul 6, 2026

ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10…

CVSS 9.1 · Critical

CVE-2026-14620

Published Jul 3, 2026

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-chang…

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-54753

Published Jun 26, 2026

Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local HTTP server started by nx graph sent Access-Control-Allow-Or…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-55454

Published Jun 24, 2026

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default —…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48783

Published Jun 17, 2026

Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accepted a signed token and applied subscription-enforcement side…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-12060

Published Jun 12, 2026

Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering technique…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-7516

Published Jun 10, 2026

A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in brow…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-47899

Published Jun 9, 2026

The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers without proper path validation. An attacker with JavaScript exe…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-41283

Published Jun 4, 2026

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of s…

CVSS 9.9 · Critical
evidence mentions
7
Buzz score
36.8

CVE-2026-44698

Published May 29, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion a…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44798

Published May 28, 2026

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to…

CVSS 7.1 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-44836

Published May 26, 2026

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the preview route derives an example name fr…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-4051

Published May 26, 2026

IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is not proper…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33584

Published May 13, 2026

Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensitive debug information such as metrics and health data. Th…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-33583

Published May 13, 2026

Exposure of the QKEY (used as input into the ‘OTA-Quantum’ device registration process) and internal system keys via an unauthenticated and unencrypted HTTP GET method in the Ar…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8108

Published May 12, 2026

The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions.

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-8109

Published May 12, 2026

An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6402

Published May 12, 2026

webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 177 CVEsPage 1 of 8