Skip to main content

CWE archive

CWE-94 CVEs

Programmatic archive

6,682 CVEs tagged with CWE-941,967 Critical, 2,231 High, 1,606 Medium, 877 Low, 1 Unrated.

CVE-2026-44698

Published May 29, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion a…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45374

Published May 28, 2026

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults t…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-45353

Published May 28, 2026

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-45311

Published May 28, 2026

CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it r…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45058

Published May 28, 2026

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-43898

Published May 28, 2026

SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runti…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-45261

Published May 28, 2026

GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execution vulnerability exists in the Tauri-based GitButler deskt…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44672

Published May 28, 2026

mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arb…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-32999

Published May 28, 2026

Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privil…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45136

Published May 27, 2026

claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.sh (introduced in v3.5.0) interpolates Claude Code's hook s…

CVSS 8.6 · High
evidence mentions
3
Buzz score
23.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44888

Published May 27, 2026

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplied numeric config values (e.g.,…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44887

Published May 27, 2026

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be injected…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-42879

Published May 27, 2026

FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted file upload vulnerability exists in FacturaScripts' produ…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45719

Published May 27, 2026

Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation parameter from the request body that is interpolated direct…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-44346

Published May 27, 2026

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yaml containing a newline-injecte…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-37713

Published May 27, 2026

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/class/commonobject.class.php.

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-37712

Published May 27, 2026

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, call_user…

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-37711

Published May 27, 2026

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/actions_addupdatedelete.inc.php

CVSS 7.3 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-8832

Published May 27, 2026

The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and includin…

CVSS 8.8 · High
evidence mentions
9
Buzz score
38.0

CVE-2026-6169

Published May 27, 2026

The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plugin using the BladeOne templat…

CVSS 7.2 · High
evidence mentions
5
Buzz score
32.9

CVE-2026-48962

Published May 27, 2026

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied ou…

CVSS 7.3 · High
evidence mentions
19
Buzz score
50.0

CVE-2026-9608

Published May 27, 2026

A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator Backend. Executing a…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-9568

Published May 26, 2026

A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the compon…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
24.4
Showing 301-325 of 6,682 CVEsPage 13 of 268