Skip to main content

CWE archive

CWE-1287 CVEs

Programmatic archive

146 CVEs tagged with CWE-128711 Critical, 58 High, 68 Medium, 9 Low, 0 Unrated.

CVE-2025-52883

Published Jun 24, 2025

Meshtastic-Android is an Android application for the mesh radio software Meshtastic. Prior to version 2.5.21, an attacker is able to send an unencrypted direct message to a victim…

CVSS 5.3 · Medium

CVE-2025-0325

Published Jun 2, 2025

A Guard Tour VAPIX API parameter allowed the use of arbitrary values and can be incorrectly called, allowing an attacker to block access to the guard tour configuration page in th…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-40911

Published May 27, 2025

Net::CIDR::Set versions 0.10 through 0.13 for Perl does not properly handle leading zero characters in IP CIDR address strings, which could allow attackers to bypass access contro…

CVSS 6.5 · Medium

CVE-2025-41650

Published May 27, 2025

An unauthenticated remote attacker can exploit input validation in cmd services of the devices, allowing them to disrupt system operations and potentially cause a denial-of-servic…

CVSS 7.5 · High

CVE-2025-20155

Published May 7, 2025

A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system. This vulnerabilit…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46342

Published Apr 30, 2025

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it may happen that policy rules using namespace selector(s) i…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-41395

Published Apr 24, 2025

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32442

Published Apr 18, 2025

Fastify is a fast and low overhead web framework, for Node.js. In versions 5.0.0 to 5.3.0 as well as version 4.29.0, applications that specify different validation strategies for…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42189

Published Apr 15, 2025

HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3070

Published Apr 2, 2025

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1558

Published Mar 24, 2025

Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via messag…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47262

Published Mar 4, 2025

Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a race condition attack allowing for an attacker to block ac…

CVSS 5.3 · Medium

CVE-2024-56908

Published Feb 13, 2025

In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parame…

CVSS 6.8 · Medium

CVE-2024-12756

Published Feb 11, 2025

An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24876

Published Feb 11, 2025

The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the vi…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-24804

Published Feb 5, 2025

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According t…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8125

Published Feb 4, 2025

Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection.  A bad actor with the required OpenText Co…

CVSS 5.4 · Medium

CVE-2025-20630

Published Jan 16, 2025

Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20621

Published Jan 16, 2025

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0476

Published Jan 16, 2025

Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a cha…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-21083

Published Jan 15, 2025

Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20088

Published Jan 15, 2025

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to caus…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 146 CVEsPage 4 of 6