Skip to main content

CWE archive

CWE-116 CVEs

Programmatic archive

475 CVEs tagged with CWE-11664 Critical, 155 High, 215 Medium, 41 Low, 0 Unrated.

CVE-2026-1011

Published Jan 16, 2026

A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitization. Although the client interf…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22712

Published Jan 9, 2026

Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - ApprovedRevs Extension allows Input…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-59158

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a s…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-68460

Published Dec 18, 2025

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-12734

Published Dec 11, 2025

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8405

Published Dec 11, 2025

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authen…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-42896

Published Dec 9, 2025

SAP BusinessObjects Business Intelligence Platform lets an unauthenticated remote attacker send crafted requests through the URL parameter that controls the login page error messa…

CVSS 5.4 · Medium

CVE-2025-66548

Published Dec 5, 2025

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Prior to 1.12.7, 1.14.4, and 1.15.1, fi…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9127

Published Dec 4, 2025

A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13742

Published Nov 27, 2025

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-64325

Published Nov 18, 2025

Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipulated X-E…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-40547

Published Nov 18, 2025

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires admi…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-11085

Published Nov 11, 2025

A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in the execution of malicious JavaScript, allowing for account…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-63785

Published Nov 7, 2025

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occurs because user-supplied input…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61084

Published Nov 5, 2025

MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: header of SMTP DATA. An attacker can craft a From: header wi…

CVSS 7.1 · High

CVE-2021-47694

Published Oct 30, 2025

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functio…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46583

Published Oct 27, 2025

There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service interface, allowi…

CVSS 5.3 · Medium

CVE-2025-11713

Published Oct 14, 2025

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when runnin…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-11712

Published Oct 14, 2025

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-61912

Published Oct 10, 2025

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a b…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55903

Published Oct 10, 2025

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To" address field within the estimate module. As a result, ar…

CVSS 8.3 · High

CVE-2025-61773

Published Oct 9, 2025

pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient input validation in both the C…

CVSS 8.1 · High

CVE-2025-0607

Published Oct 6, 2025

Improper Encoding or Escaping of Output vulnerability in Logo Software Inc. Logo Cloud allows Phishing. This issue affects Logo Cloud: before 2.57.

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-60787

Published Oct 3, 2025

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration…

CVSS 7.2 · High
Buzz score
5.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-59936

Published Sep 27, 2025

get-jwks contains fetch utils for JWKS keys. In versions prior to 11.0.2, a vulnerability in get-jwks can lead to cache poisoning in the JWKS key-fetching mechanism. When the iss…

CVSS 9.4 · Critical
Showing 126-150 of 475 CVEsPage 6 of 19