Skip to main content

CWE archive

CWE-790 CVEs

Programmatic archive

15 CVEs tagged with CWE-7903 Critical, 7 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-11331

Published Jul 22, 2026

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ proc…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9

CVE-2026-9658

Published May 28, 2026

Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffective at blocking header…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-2328

Published Mar 30, 2026

An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, resulting in exposure of…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-15576

Published Mar 9, 2026

If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may n…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0431

Published Mar 19, 2025

Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integr…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-47984

Published Dec 13, 2024

Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability. A User with Remote access could potentially exploit this vulnerability, leading to the disru…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42416

Published Sep 5, 2024

The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Mali…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43443

Published Aug 26, 2024

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cro…

CVSS 4.9 · Medium

CVE-2024-43442

Published Aug 26, 2024

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in  OTRS (System Configuration modules) and ((OTRS)) Community Edition allows C…

CVSS 4.9 · Medium

CVE-2024-6540

Published Jul 15, 2024

Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user to download a list of tickets c…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31616

Published Apr 23, 2024

An issue discovered in RG-RSR10-01G-T(W)-S and RG-RSR10-01G-T(WA)-S routers with firmware version RSR10-01G-T-S_RSR_3.0(1)B9P2, Release(07150910) allows attackers to execute arbit…

CVSS 8.8 · High

CVE-2023-45239

Published Oct 6, 2023

A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker who can control the username, rem-addr,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-22578

Published Feb 16, 2023

Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-43802

Published Dec 9, 2021

Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allow the attacker to gain admin p…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1