Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,626 CVEs tagged with CWE-77953 Critical, 1,471 High, 772 Medium, 428 Low, 2 Unrated.

CVE-2026-6576

Published Apr 19, 2026

A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanager/api/commonapi.py of the comp…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-30898

Published Apr 18, 2026

An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-35682

Published Apr 17, 2026

Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., starting telnetd), resulting in root‑…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-21709

Published Apr 17, 2026

A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.

CVSS 6.7 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-41153

Published Apr 17, 2026

In JetBrains Junie before 252.549.29 command execution was possible via malicious project file

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6483

Published Apr 17, 2026

A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the file /cgi-bin/internet.cgi. The manipulation results in os…

CVSS 7.3 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-20186

Published Apr 15, 2026

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affect…

CVSS 9.9 · Critical
evidence mentions
5
Buzz score
35.9
Vendor/product tagsBeta · best-effort

CVE-2026-30625

Published Apr 15, 2026

Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary comman…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-30624

Published Apr 15, 2026

Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP servers using a JSON…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30617

Published Apr 15, 2026

LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attacker can access the publicly exp…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-30616

Published Apr 15, 2026

Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted network requests to the network-accessib…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-30615

Published Apr 15, 2026

A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML c…

CVSS 8.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-30461

Published Apr 15, 2026

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_sub…

CVSS 8.3 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-53412

Published Apr 15, 2026

Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection…

CVSS 8.4 · High

CVE-2026-23653

Published Apr 14, 2026

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-4786

Published Apr 13, 2026

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have command…

CVSS 7.0 · High
evidence mentions
58
Buzz score
49.5

CVE-2026-6219

Published Apr 13, 2026

A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of the component Compressor Feat…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
27.5
Showing 376-400 of 3,626 CVEsPage 16 of 146