Skip to main content

CWE archive

CWE-791 CVEs

Programmatic archive

37 CVEs tagged with CWE-7912 Critical, 10 High, 15 Medium, 10 Low, 0 Unrated.

CVE-2026-11998

Published Jun 24, 2026

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the conte…

CVSS 7.6 · High
evidence mentions
6
Buzz score
37.5

CVE-2026-48208

Published Jun 1, 2026

An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9498

Published May 25, 2026

A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulatio…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-47323

Published May 19, 2026

Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cx…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-8740

Published May 17, 2026

A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/Te…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-44232

Published May 12, 2026

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.3, every IPv6 category bypasses is_url_safe. This vulnerability i…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-7164

Published Apr 30, 2026

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packe…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-6984

Published Apr 25, 2026

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Das…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-5987

Published Apr 9, 2026

A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFreemarkerView.doRender of the file publiccms-parent/publiccms-…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-5559

Published Apr 5, 2026

A vulnerability has been found in AntaresMugisho PyBlade 0.1.8-alpha/0.1.9-alpha. The affected element is the function _is_safe_ast of the file sandbox.py of the component AST Val…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-3725

Published Mar 8, 2026

A flaw has been found in 1024-lab/lab1024 SmartAdmin up to 3.29. Affected by this issue is the function freemarkerResolverContent of the file sa-base/src/main/java/net/lab1024/sa/…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-3714

Published Mar 8, 2026

A vulnerability has been found in OpenCart 4.0.2.3. Affected by this issue is the function Save of the file admin/controller/design/template.php of the component Incomplete Fix CV…

CVSS 5.1 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-2969

Published Feb 23, 2026

A flaw has been found in datapizza-labs datapizza-ai 0.0.2. Affected is the function ChatPromptTemplate of the file datapizza-ai-core/datapizza/modules/prompt/prompt.py of the com…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-14731

Published Dec 16, 2025

A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2025-59303

Published Oct 8, 2025

HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can res…

CVSS 6.4 · Medium

CVE-2025-9094

Published Aug 17, 2025

A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6761

Published Jun 27, 2025

A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical. Affected by this issue is the function plugin.buildMobileP…

CVSS 5.5 · Medium

CVE-2025-6518

Published Jun 23, 2025

A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/si…

CVSS 2.1 · Low

CVE-2025-2336

Published Jun 4, 2025

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS's 'ngSanitize' module allows attackers to bypass common image s…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
31.1

CVE-2025-0324

Published Jun 2, 2025

The VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-5325

Published May 29, 2025

A vulnerability has been found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified as critical. Affected by this vulnerability is an unknown f…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0716

Published Apr 29, 2025

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS allows attackers to bypass common image source restrictions. Th…

CVSS 4.8 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2025-3841

Published Apr 21, 2025

A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.p…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45481

Published Mar 25, 2025

An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may allow an authenticated local attacker to authenticate as anoth…

CVSS 8.5 · High
Showing 1-25 of 37 CVEsPage 1 of 2