Skip to main content

CWE archive

CWE-76 CVEs

Programmatic archive

12 CVEs tagged with CWE-763 Critical, 4 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2026-55723

Published Jul 15, 2026

When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGI…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-11311

Published Jun 17, 2026

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric.…

CVSS 8.6 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-28292

Published Mar 10, 2026

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixe…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
41.5
Vendor/product tagsBeta · best-effort

CVE-2024-4897

Published Jul 2, 2024

parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp31…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34359

Published May 14, 2024

llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2024-2952

Published Apr 10, 2024

BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerability arises from the `hf_chat_template` method processing the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-21600

Published Jan 12, 2024

An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1149

Published Mar 2, 2023

Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1