Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,626 CVEs tagged with CWE-77953 Critical, 1,471 High, 772 Medium, 428 Low, 2 Unrated.

CVE-2026-16763

Published Jul 23, 2026

A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2024-58354

Published Jul 23, 2026

cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_ta…

CVSS 8.5 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-47670

Published Jul 23, 2026

DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
20.0
Public PoC observed

CVE-2026-16735

Published Jul 23, 2026

A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Change…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-16733

Published Jul 23, 2026

A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handl…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-16631

Published Jul 23, 2026

A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. Th…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-16630

Published Jul 22, 2026

A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipu…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-16629

Published Jul 22, 2026

A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the compo…

CVSS 4.8 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-16628

Published Jul 22, 2026

A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a mani…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
28.5

CVE-2026-16492

Published Jul 22, 2026

A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the compone…

CVSS 2.0 · Low
evidence mentions
9
Buzz score
29.5

CVE-2026-16489

Published Jul 22, 2026

A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-16488

Published Jul 22, 2026

A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project…

CVSS 1.3 · Low
evidence mentions
10
Buzz score
32.0

CVE-2026-47708

Published Jul 21, 2026

MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpo…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-47690

Published Jul 21, 2026

MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulner…

CVSS 7.5 · High
evidence mentions
6
Buzz score
24.5

CVE-2026-44879

Published Jul 21, 2026

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands.…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16448

Published Jul 21, 2026

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343,…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
34.5

CVE-2026-59846

Published Jul 21, 2026

A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintende…

CVSS 3.9 · Low
evidence mentions
3
Buzz score
23.9

CVE-2026-16133

Published Jul 18, 2026

A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to…

CVSS 1.3 · Low
evidence mentions
8
Buzz score
30.0

CVE-2025-71392

Published Jul 18, 2026

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-52199

Published Jul 17, 2026

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-30623

Published Jul 15, 2026

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration s…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2025-65720

Published Jul 15, 2026

An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2026-46709

Published Jul 15, 2026

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-56197

Published Jul 14, 2026

Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.

CVSS 8.8 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-55145

Published Jul 14, 2026

Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort
Showing 1-25 of 3,626 CVEsPage 1 of 146