Skip to main content

CWE archive

CWE-78 CVEs

Programmatic archive

6,183 CVEs tagged with CWE-781,976 Critical, 3,127 High, 890 Medium, 190 Low, 0 Unrated.

CVE-2026-44346

Published May 27, 2026

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yaml containing a newline-injecte…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44345

Published May 27, 2026

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/tem…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-36045

Published May 27, 2026

picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command…

CVSS 7.3 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-36044

Published May 27, 2026

@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell co…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-40852

Published May 27, 2026

A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration valu…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-8450

Published May 27, 2026

HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets m…

CVSS 9.1 · Critical
evidence mentions
11
Buzz score
44.9

CVE-2026-9207

Published May 27, 2026

Tanium addressed an unauthorized code execution vulnerability in Connect.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44444

Published May 26, 2026

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the stati…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-9560

Published May 26, 2026

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC c…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48695

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fas…

CVSS 8.1 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-48694

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php,…

CVSS 8.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-46624

Published May 26, 2026

Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9565

Published May 26, 2026

A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the compon…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-44723

Published May 26, 2026

Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strin…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-48687

Published May 26, 2026

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastn…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-9543

Published May 26, 2026

A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Int…

CVSS 8.9 · High
evidence mentions
5
Buzz score
29.4

CVE-2026-9534

Published May 26, 2026

A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a man…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-9533

Published May 26, 2026

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handle…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-9532

Published May 26, 2026

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-9531

Published May 26, 2026

A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This man…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-9515

Published May 26, 2026

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handl…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-9514

Published May 25, 2026

A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of the file /cgi-bin/cstecgi.cgi of the component Setting Handle…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-9513

Published May 25, 2026

A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. E…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-9512

Published May 25, 2026

A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Settin…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4
Showing 351-375 of 6,183 CVEsPage 15 of 248