Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,612 CVEs tagged with CWE-284701 Critical, 1,857 High, 2,521 Medium, 519 Low, 14 Unrated.

CVE-2026-16451

Published Jul 21, 2026

A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-47396

Published Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-28321

Published Jul 21, 2026

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute co…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-28307

Published Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows de…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-28306

Published Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-28304

Published Jul 21, 2026

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Win…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-16447

Published Jul 21, 2026

A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument File…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2025-66390

Published Jul 21, 2026

In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registrat…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-16407

Published Jul 21, 2026

Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-16387

Published Jul 21, 2026

Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.9

CVE-2026-16365

Published Jul 21, 2026

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-16332

Published Jul 21, 2026

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16331

Published Jul 21, 2026

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Mal…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16330

Published Jul 21, 2026

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argume…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16329

Published Jul 21, 2026

A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Han…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-16327

Published Jul 21, 2026

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument F…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
34.5

CVE-2026-55550

Published Jul 20, 2026

NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55544

Published Jul 20, 2026

NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-47255

Published Jul 20, 2026

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to…

CVSS 8.2 · High
evidence mentions
7
Buzz score
25.8

CVE-2026-16324

Published Jul 20, 2026

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-62414

Published Jul 20, 2026

The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-60030

Published Jul 20, 2026

The Joomla extension Quix Page Builder Pro is vulnerable to an improper access control. Authenticated users could upload media files regardless of their media management permissio…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-46415

Published Jul 20, 2026

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender use…

CVSS 8.2 · High
evidence mentions
4
Buzz score
26.1

CVE-2026-12972

Published Jul 20, 2026

The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated user…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-16226

Published Jul 19, 2026

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation o…

CVSS 5.1 · Medium
evidence mentions
5
Buzz score
27.9
Showing 151-175 of 5,612 CVEsPage 7 of 225