Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,181 CVEs tagged with CWE-781,976 Critical, 3,127 High, 890 Medium, 188 Low, 0 Unrated.

CVE-2026-9645

Published May 28, 2026

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44466

Published May 28, 2026

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands nest…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44465

Published May 28, 2026

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonitor Git configuratio…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44463

Published May 28, 2026

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking pro…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44461

Published May 28, 2026

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable keys are inserted with…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44604

Published May 28, 2026

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory…

CVSS 7.0 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-45322

Published May 27, 2026

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injecti…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9208

Published May 27, 2026

Tanium addressed an unauthorized code execution vulnerability in Connect.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45152

Published May 27, 2026

uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability exists in uniget due to unsafe execution of the check field f…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45136

Published May 27, 2026

claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook s…

CVSS 8.6 · High
evidence mentions
3
Buzz score
23.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44713

Published May 27, 2026

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the user's $TMUX environment variable, splits it on commas, and…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44712

Published May 27, 2026

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the config causes root RCE when pamusb-…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44709

Published May 27, 2026

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment variable and execute…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44724

Published May 27, 2026

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces()…

CVSS 7.8 · High
evidence mentions
5
Buzz score
30.9

CVE-2026-44590

Published May 27, 2026

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command i…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45087

Published May 27, 2026

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds t…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-44346

Published May 27, 2026

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yaml containing a newline-injecte…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44345

Published May 27, 2026

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/tem…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 326-350 of 6,181 CVEsPage 14 of 248