Skip to main content

CWE archive

CWE-74 CVEs

Programmatic archive

4,976 CVEs tagged with CWE-74242 Critical, 531 High, 3,009 Medium, 1,193 Low, 1 Unrated.

CVE-2026-8785

Published May 18, 2026

A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-8777

Published May 18, 2026

A vulnerability was found in Edimax BR-6428NS 1.10. This issue affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. Perf…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-8774

Published May 18, 2026

A vulnerability was detected in Edimax BR-6228NC 1.22. Affected by this issue is the function mp of the file /goform/mp of the component POST Request Handler. The manipulation of…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-8773

Published May 18, 2026

A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-8772

Published May 18, 2026

A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admin Endpoint. Executing a manipulation can lead to sql inject…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-8771

Published May 18, 2026

A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxG…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-8753

Published May 17, 2026

A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8734

Published May 17, 2026

A vulnerability was determined in Oinone Pamirs up to 7.2.0. Affected by this issue is the function RSQLToSQLNodeConnector.makeVariable of the component queryListByWrapper Interfa…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-8724

Published May 17, 2026

A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard. The m…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-42334

Published May 14, 2026

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44458

Published May 13, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44455

Published May 13, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44246

Published May 12, 2026

nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net Issue Triage workflow in .github/workflows/issue-tria…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42838

Published May 12, 2026

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate pr…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-41109

Published May 12, 2026

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a…

CVSS 8.8 · High
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2026-33833

Published May 12, 2026

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing ov…

CVSS 8.2 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-8346

Published May 12, 2026

A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in comma…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-8345

Published May 11, 2026

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-8344

Published May 11, 2026

A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulati…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-8231

Published May 10, 2026

A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0. This affects an unknown function of the file /deleteorder.php. The manipulation of the argument ID…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-8211

Published May 9, 2026

A vulnerability was detected in codelibs Fess up to 15.5.1. Affected by this issue is the function update of the file org/codelibs/fess/app/web/admin/design/AdminDesignAction.java…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8210

Published May 9, 2026

A security vulnerability has been detected in aandrew-me tgpt up to 2.11.1 on Linux/macOS. Affected by this vulnerability is the function helper.Update of the file helper.go of th…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-41885

Published May 8, 2026

i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for Deno. Prior to version 9.0.2, i18next-locize-backend interpo…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-67486

Published May 8, 2026

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code ex…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort
Showing 376-400 of 4,976 CVEsPage 16 of 200