Skip to main content

CWE archive

CWE-829 CVEs

Programmatic archive

298 CVEs tagged with CWE-82959 Critical, 165 High, 65 Medium, 8 Low, 1 Unrated.

CVE-2026-66141

Published Jul 24, 2026

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-65908

Published Jul 23, 2026

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64811

Published Jul 23, 2026

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64809

Published Jul 23, 2026

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64808

Published Jul 23, 2026

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64807

Published Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64806

Published Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64805

Published Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64804

Published Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47398

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate to…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-45711

Published Jul 20, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command downloads every message from a remote Ma…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-44359

Published Jul 20, 2026

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_ta…

CVSS 10.0 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-16085

Published Jul 18, 2026

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of the file pkg/agent/context.go. Such manipulation leads to…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-57860

Published Jul 17, 2026

ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without user con…

CVSS 8.4 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-62222

Published Jul 17, 2026

OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control o…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-59867

Published Jul 16, 2026

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-59865

Published Jul 16, 2026

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency n…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-59864

Published Jul 16, 2026

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_temp…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-50562

Published Jul 15, 2026

FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/w…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-40501

Published Jul 15, 2026

Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerability in SearchService that allows remote attackers to execute arbitr…

CVSS 8.6 · High
evidence mentions
3
Buzz score
21.9

CVE-2026-24226

Published Jul 14, 2026

NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-57102

Published Jul 14, 2026

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

CVSS 8.8 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-15519

Published Jul 13, 2026

A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. Performing a manipulation…

CVSS 1.3 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-59831

Published Jul 9, 2026

GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution becau…

CVSS 4.4 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-50195

Published Jul 1, 2026

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate th…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 298 CVEsPage 1 of 12