Skip to main content

CWE archive

CWE-821 CVEs

Programmatic archive

13 CVEs tagged with CWE-8212 Critical, 3 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-56132

Published Jun 19, 2026

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sh…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-43198

Published May 6, 2026

In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn…

CVSS 9.8 · Critical
evidence mentions
21
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-21919

Published Apr 9, 2026

An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-58133

Published Apr 6, 2025

In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarting this node, concurrent writes by logger.go to a map are m…

CVSS 4.0 · Medium

CVE-2024-58132

Published Apr 6, 2025

In chainmaker-go (aka ChainMaker) before 2.3.6, multiple updates to a single node's configuration can cause other normal nodes to perform concurrent read and write operations on a…

CVSS 4.0 · Medium

CVE-2024-58131

Published Apr 6, 2025

FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a malicious node (that has modified the codebase to allow a lar…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6657

Published Oct 11, 2024

A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuously connect and disconnect to the peripheral. A hard reset…

CVSS 6.5 · Medium

CVE-2024-4278

Published Sep 26, 2024

An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5755

Published Jun 27, 2024

In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the creation of multiple accounts…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1739

Published Apr 16, 2024

lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email ad…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-1902

Published Apr 10, 2024

lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name without proper authorization. The vulnerability stems from the la…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5088

Published Nov 3, 2023

A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). Th…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1