Skip to main content

CWE archive

CWE-99 CVEs

Programmatic archive

57 CVEs tagged with CWE-993 Critical, 11 High, 25 Medium, 18 Low, 0 Unrated.

CVE-2026-15186

Published Jul 9, 2026

A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. The manipulation…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-13493

Published Jun 28, 2026

A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the component Workf…

CVSS 1.3 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-12207

Published Jun 15, 2026

A security flaw has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5380834216b09ed. Impacted is the function actionGetPatientById of the file app\modules\medi…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-10624

Published Jun 2, 2026

A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file /detailview.php of the compo…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
34.5

CVE-2026-10299

Published Jun 1, 2026

A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulat…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-10168

Published May 31, 2026

A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function ma…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-9438

Published May 25, 2026

A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file courseDel.php. The man…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-33603

Published May 12, 2026

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself betwe…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7303

Published Apr 28, 2026

A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/…

CVSS 2.9 · Low
evidence mentions
7
Buzz score
27.3

CVE-2026-5414

Published Apr 2, 2026

A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionality of the file /omnidocs/WebApiRequestRedirection. The mani…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2026-5031

Published Mar 29, 2026

A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_route=settings/users-view/ of the component Endpoint. The m…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-3693

Published Mar 8, 2026

A flaw has been found in Shy2593666979 AgentChat up to 2.3.0. This issue affects the function get_user_info/update_user_info of the file /src/backend/agentchat/api/v1/user.py of t…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2025-12919

Published Nov 9, 2025

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Ha…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-12918

Published Nov 9, 2025

A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an unknown function of the file /dashboard/fees/fee-invoices/ o…

CVSS 1.3 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2025-12270

Published Oct 27, 2025

A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The impacted element is an unknown function of the file /api/v1/assignments/{assignmen…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-43491

Published Sep 9, 2025

A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the filesystem, which might lead to SYSTEM level privileges being…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9619

Published Aug 29, 2025

A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of the file /basico/webservice/imprimir-danfe/id/. Performing…

CVSS 6.9 · Medium

CVE-2025-9264

Published Aug 21, 2025

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.j…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9263

Published Aug 20, 2025

A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controlle…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8793

Published Aug 10, 2025

A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argumen…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6534

Published Jun 24, 2025

A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-2410

Published May 22, 2025

Port manipulation vulnerabilities in ASPECT provide attackers with the ability to con-trol TCP/IP port access if session administrator credentials become compromised. This issue a…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-3855

Published Apr 22, 2025

A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0756

Published Apr 16, 2025

Overview   The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resou…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-3405

Published Apr 8, 2025

A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file…

CVSS 5.3 · Medium
Showing 1-25 of 57 CVEsPage 1 of 3