Skip to main content

CWE archive

CWE-840 CVEs

Programmatic archive

89 CVEs tagged with CWE-8405 Critical, 16 High, 55 Medium, 13 Low, 0 Unrated.

CVE-2026-58558

Published Jul 15, 2026

Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-13571

Published Jun 29, 2026

A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a manipulation of the argumen…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-41973

Published Jun 9, 2026

Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-11465

Published Jun 7, 2026

A security flaw has been discovered in songquanpeng one-api up to 0.6.11-preview.7. Affected by this issue is the function Redeem of the file model/redemption.go of the component…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-8738

Published May 17, 2026

A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pa…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2026-41971

Published May 15, 2026

Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-41968

Published May 15, 2026

Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-41967

Published May 15, 2026

Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-41966

Published May 15, 2026

Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-41965

Published May 15, 2026

Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 5.6 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-41961

Published May 15, 2026

Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-1322

Published May 14, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authentica…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-1274

Published Apr 23, 2026

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-5812

Published Apr 8, 2026

A security flaw has been discovered in SourceCodester Pharmacy Product Management System 1.0. This affects an unknown part of the file add-sales.php of the component POST Paramete…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-5811

Published Apr 8, 2026

A vulnerability was identified in SourceCodester Online Food Ordering System 1.0. Affected by this issue is the function save_product of the file /Actions.php of the component POS…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-4547

Published Mar 22, 2026

A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of t…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-28550

Published Mar 5, 2026

Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 4.0 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-1600

Published Jan 29, 2026

A vulnerability was identified in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The impacted element is an unknown function of the file /hungry/addtocart o…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2026-1599

Published Jan 29, 2026

A vulnerability was determined in Bdtask Bhojon All-In-One Restaurant Management System up to 20260116. The affected element is an unknown function of the file /hungry/placeorder…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2025-14559

Published Jan 21, 2026

A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized us…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
26.1

CVE-2025-13239

Published Nov 16, 2025

A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of the…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-6601

Published Oct 27, 2025

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated u…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-58289

Published Oct 11, 2025

Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10868

Published Sep 26, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain string conversion methods exh…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-8991

Published Aug 15, 2025

A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file /admin/config/express of the component Bu…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 89 CVEsPage 1 of 4