Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,180 CVEs tagged with CWE-781,976 Critical, 3,126 High, 890 Medium, 188 Low, 0 Unrated.

CVE-2026-10805

Published Jun 4, 2026

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Descript…

CVSS 6.7 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-41010

Published Jun 4, 2026

ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-41011

Published Jun 4, 2026

PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from releas…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-36576

Published Jun 3, 2026

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
26.1

CVE-2026-47294

Published Jun 1, 2026

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a netw…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-10279

Published Jun 1, 2026

A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts of the component switch_pane/w…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10273

Published Jun 1, 2026

A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a mani…

CVSS 5.5 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-10219

Published Jun 1, 2026

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_fil…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-10214

Published Jun 1, 2026

A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-49366

Published May 29, 2026

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45633

Published May 29, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket en…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45632

Published May 29, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45630

Published May 29, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allow…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45629

Published May 29, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any or…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45626

Published May 29, 2026

Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path quer…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45662

Published May 29, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes do…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45578

Published May 29, 2026

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.ph…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 301-325 of 6,180 CVEsPage 13 of 248