Skip to main content

CWE archive

CWE-777 CVEs

Programmatic archive

3 CVEs tagged with CWE-7770 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-56021

Published Jun 18, 2026

Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
32.6

CVE-2026-40110

Published May 5, 2026

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against…

CVSS 7.6 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-39087

Published Apr 23, 2026

ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.

CVSS 6.4 · Medium
evidence mentions
3
Buzz score
25.4
Showing 1-3 of 3 CVEsPage 1 of 1