Skip to main content

CWE archive

CWE-94 CVEs

Programmatic archive

6,703 CVEs tagged with CWE-941,971 Critical, 2,248 High, 1,606 Medium, 877 Low, 1 Unrated.

CVE-2026-54666

Published Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys throug…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-54664

Published Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.sc…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-54662

Published Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into a…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-54661

Published Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates ser…

CVSS 8.3 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-14900

Published Jul 29, 2026

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-13423

Published Jul 29, 2026

The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied P…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-55415

Published Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. F…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-54656

Published Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. F…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-54655

Published Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type values parsed by src/datamodel_code_generator/parser/jsonsch…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-54654

Published Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template-data comment field is rendered into Python comments i…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-54653

Published Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. F…

CVSS 8.8 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-54621

Published Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_code_generator/model/template/Uni…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-66745

Published Jul 28, 2026

Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrati…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-66748

Published Jul 28, 2026

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary…

CVSS 8.7 · High
evidence mentions
6
Buzz score
31.0

CVE-2026-65880

Published Jul 28, 2026

Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include t…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-56747

Published Jul 27, 2026

Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execut…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-14289

Published Jul 27, 2026

The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-63720

Published Jul 26, 2026

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supply…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-65693

Published Jul 24, 2026

Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecti…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-16801

Published Jul 24, 2026

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with varia…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-16800

Published Jul 24, 2026

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedu…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-71389

Published Jul 23, 2026

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request ha…

CVSS 10.0 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-60122

Published Jul 23, 2026

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute…

CVSS 8.5 · High
evidence mentions
3
Buzz score
20.4

CVE-2026-47722

Published Jul 23, 2026

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the ope…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-47668

Published Jul 23, 2026

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
18.9
Showing 1-25 of 6,703 CVEsPage 1 of 269