Skip to main content

CWE archive

CWE-755 CVEs

Programmatic archive

581 CVEs tagged with CWE-75526 Critical, 262 High, 268 Medium, 25 Low, 0 Unrated.

CVE-2026-42792

Published Jul 27, 2026

Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemo…

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
30.9

CVE-2026-48036

Published Jul 24, 2026

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in…

CVSS 8.4 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-16730

Published Jul 24, 2026

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, ca…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-62994

Published Jul 16, 2026

CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with…

CVSS 3.7 · Low
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-59162

Published Jul 10, 2026

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks onl…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-54775

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processi…

CVSS 6.5 · Medium
evidence mentions
6
Buzz score
24.5

CVE-2026-59927

Published Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and no…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-55577

Published Jul 1, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in the MVG d…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44505

Published Jun 10, 2026

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in handle_dht_…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2023-43686

Published Jun 9, 2026

An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser conf…

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-40371

Published Jun 9, 2026

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

CVSS 8.8 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-49235

Published Jun 8, 2026

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49232

Published Jun 8, 2026

Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such as running out of file descriptors. This condition can be tr…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9516

Published Jun 3, 2026

Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, deco…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-48524

Published May 28, 2026

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown k…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44325

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type-confusion bug fami…

CVSS 7.5 · High
evidence mentions
4
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44319

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire process when a stored PFD-subscription notifyUri cannot be rea…

CVSS 7.5 · High
evidence mentions
4
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44902

Published May 27, 2026

opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus expo…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48961

Published May 27, 2026

IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID. When…

CVSS 7.3 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-42545

Published May 12, 2026

Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI application returns an invalid HTTP response header name or v…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-8162

Published May 12, 2026

[email protected] and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose fi…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-34065

Published Apr 22, 2026

nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node…

CVSS 7.5 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-40074

Published Apr 10, 2026

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redirect, when called from inside the handle server hook with a…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 581 CVEsPage 1 of 24