Skip to main content

CWE archive

CWE-830 CVEs

Programmatic archive

12 CVEs tagged with CWE-8300 Critical, 5 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2025-65109

Published Nov 21, 2025

Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may…

CVSS 8.5 · High

CVE-2025-64496

Published Nov 8, 2025

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerability in the Direct…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-46652

Published Apr 26, 2025

In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an extraction from an archive file that bears Mark-of-the-Web, Mark-of-the-Web is not p…

CVSS 6.1 · Medium

CVE-2025-43703

Published Apr 16, 2025

An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access to the internal API (even though the attacker has no knowle…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-33028

Published Apr 15, 2025

In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows attackers to bypass the Mark-of-t…

CVSS 6.1 · Medium

CVE-2025-33027

Published Apr 15, 2025

In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affe…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-33026

Published Apr 15, 2025

In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected insta…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42381

Published Jul 31, 2024

os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an ELF file with a…

CVSS 8.3 · High

CVE-2024-35180

Published May 21, 2024

OMERO.web provides a web based client and plugin infrastructure. There is currently no escaping or validation of the `callback` parameter that can be passed to various OMERO.web e…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29944

Published Mar 22, 2024

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects De…

CVSS 8.4 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2023-2588

Published May 22, 2023

Teltonika’s Remote Management System versions prior to 4.10.0 have a feature allowing users to access managed devices’ local secure shell (SSH)/web management services over the cl…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-28162

Published Mar 12, 2021

In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1