Skip to main content

CWE archive

CWE-94 CVEs

Programmatic archive

6,681 CVEs tagged with CWE-941,966 Critical, 2,231 High, 1,606 Medium, 877 Low, 1 Unrated.

CVE-2026-10514

Published Jun 2, 2026

A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend/framework/src/main/java/cn/cordys/config/RequestParamTrimC…

CVSS 1.9 · Low
evidence mentions
9
Buzz score
29.5

CVE-2026-10301

Published Jun 2, 2026

A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of the file index.php. Performing a manipulation of the argume…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-25879

Published Jun 1, 2026

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by pr…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-10289

Published Jun 1, 2026

A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-9311

Published Jun 1, 2026

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45132

Published Jun 1, 2026

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Perso…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-45131

Published Jun 1, 2026

CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-8931

Published Jun 1, 2026

A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.

CVSS 9.4 · Critical
evidence mentions
6
Buzz score
27.5

CVE-2026-10247

Published Jun 1, 2026

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_gener…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-10246

Published Jun 1, 2026

A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medic…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-10245

Published Jun 1, 2026

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main.…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-10244

Published Jun 1, 2026

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/c…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-45505

Published Jun 1, 2026

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthes…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42588

Published Jun 1, 2026

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveM…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-10234

Published Jun 1, 2026

A vulnerability was detected in Mettle sendportal up to 3.0.1. This affects an unknown part of the file /webview/ of the component Campaign Handler. The manipulation of the argume…

CVSS 2.0 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-10228

Published Jun 1, 2026

A vulnerability was found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The impacted element is an unknown function of the file…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10175

Published May 31, 2026

A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode.…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10173

Published May 31, 2026

A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the compo…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10153

Published May 30, 2026

A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractC…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-10112

Published May 30, 2026

A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the component Dashboard Page. The manipulation of the argument Name l…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-45697

Published May 29, 2026

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) tha…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-44287

Published May 29, 2026

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the reg…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-41159

Published May 29, 2026

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows inject…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-45555

Published May 29, 2026

Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and execu…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-44698

Published May 29, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion a…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Showing 276-300 of 6,681 CVEsPage 12 of 268