Skip to main content

CWE archive

CWE-829 CVEs

Programmatic archive

315 CVEs tagged with CWE-82961 Critical, 177 High, 67 Medium, 9 Low, 1 Unrated.

CVE-2026-73073

Published Aug 18, 2026

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficie…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-73367

Published Aug 18, 2026

Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-73851

Published Aug 17, 2026

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a f…

CVSS 6.1 · Medium
evidence mentions
8
Buzz score
27.0

CVE-2026-49986

Published Aug 14, 2026

The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-19884

Published Aug 14, 2026

In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applica…

CVSS 8.4 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-6464

Published Aug 13, 2026

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-18408

Published Aug 13, 2026

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating sys…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-71471

Published Aug 12, 2026

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could ex…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-73076

Published Aug 11, 2026

Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-15560

Published Aug 11, 2026

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to l…

CVSS 8.1 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-66843

Published Aug 6, 2026

Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosi…

CVSS 2.3 · Low
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-55522

Published Aug 5, 2026

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerab…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-67623

Published Aug 5, 2026

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a rep…

CVSS 8.6 · High
evidence mentions
7
Buzz score
32.3

CVE-2026-66902

Published Aug 4, 2026

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4

CVE-2026-47781

Published Aug 4, 2026

PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initiali…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-66141

Published Jul 24, 2026

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-65908

Published Jul 23, 2026

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64811

Published Jul 23, 2026

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64809

Published Jul 23, 2026

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64808

Published Jul 23, 2026

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64807

Published Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64806

Published Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64805

Published Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 315 CVEsPage 1 of 13