Skip to main content

CWE archive

CWE-75 CVEs

Programmatic archive

36 CVEs tagged with CWE-7510 Critical, 15 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2024-58362

Published Jul 18, 2026

SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for no…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-54771

Published Jul 10, 2026

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may al…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-31908

Published Apr 14, 2026

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects A…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-29042

Published Mar 6, 2026

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell Runtime component contains a command injection vulnerabilit…

CVSS 8.9 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-27120

Published Feb 20, 2026

Leafkit is a templating language with Swift-inspired syntax. Prior to 1.4.1, htmlEscaped in leaf-kit will only escape html special characters if the extended grapheme clusters mat…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-27708

Published Dec 22, 2025

Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter.

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-61911

Published Oct 10, 2025

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter.escape_filter_chars` can be t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50213

Published Jun 24, 2025

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Pro…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-9940

Published Oct 17, 2024

The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing H…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37779

Published Sep 23, 2024

WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.

CVSS 8.8 · High

CVE-2024-24257

Published Jul 26, 2024

An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the csl/user com…

CVSS 7.5 · High

CVE-2024-39243

Published Jun 26, 2024

An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-35373

Published May 24, 2024

Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-31806

Published Apr 8, 2024

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorizat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21503

Published Mar 19, 2024

Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file…

CVSS 5.3 · Medium

CVE-2024-0801

Published Mar 13, 2024

A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-0044

Published Mar 11, 2024

In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege wit…

CVSS 6.7 · Medium
Buzz score
5.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-23274

Published Mar 8, 2024

An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to eleva…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23268

Published Mar 8, 2024

An injection issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to eleva…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27622

Published Mar 5, 2024

A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate san…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40743

Published Sep 5, 2023

** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-1758

Published Apr 5, 2023

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 36 CVEsPage 1 of 2