Skip to main content

CWE archive

CWE-841 CVEs

Programmatic archive

56 CVEs tagged with CWE-8413 Critical, 18 High, 29 Medium, 6 Low, 0 Unrated.

CVE-2026-18029

Published Jul 28, 2026

Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and sup…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-16103

Published Jul 17, 2026

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to the Client-In…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-57536

Published Jun 25, 2026

Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13223

Published Jun 25, 2026

Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from o…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-13222

Published Jun 25, 2026

Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-48505

Published Jun 22, 2026

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based mu…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46540

Published Jun 10, 2026

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, when LightBlockchain::rebranch() adopts a f…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-43974

Published Jun 8, 2026

Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server to force the client into raw protocol mode via an unsolicite…

CVSS 8.7 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-45023

Published May 28, 2026

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute end…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-8477

Published May 22, 2026

Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticated user with access to a sealed entry to…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42303

Published May 12, 2026

Fides is an open-source privacy engineering platform. From 2.75.0 to before 2.83.2, Fides deployments that enable both subject identity verification and duplicate privacy request…

CVSS 6.1 · Medium
evidence mentions
6
Buzz score
24.5

CVE-2026-43937

Published May 12, 2026

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-41259

Published Apr 23, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail dom…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34582

Published Apr 7, 2026

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being receiv…

CVSS 8.7 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-3130

Published Mar 3, 2026

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-52469

Published Mar 2, 2026

Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2026-24774

Published Feb 3, 2026

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a business logic vulnerability allows authenticated student…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13751

Published Dec 3, 2025

Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger…

CVSS 1.3 · Low
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-13129

Published Dec 1, 2025

Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information Technology Trade Contracting and Industry Ltd. Co. Onaylarım allows Functionality…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-13239

Published Nov 16, 2025

A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of the…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 56 CVEsPage 1 of 3