Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,432 CVEs tagged with CWE-285121 Critical, 391 High, 637 Medium, 283 Low, 0 Unrated.

CVE-2025-43289

Published May 26, 2026

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app may be able to access sensitive…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-46620

Published May 26, 2026

e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. The problem comes down to how se…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-9484

Published May 25, 2026

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassro…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
32.3

CVE-2026-9483

Published May 25, 2026

A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-9410

Published May 25, 2026

A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnerability affects unknown code of the file /profile of the com…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-9409

Published May 25, 2026

A flaw has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This affects an unknown part of the file /user of the component User Management…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-9397

Published May 24, 2026

A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the component OTA Update Installation Hand…

CVSS 8.2 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-9376

Published May 24, 2026

A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCenter Article Submiss…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-9306

Published May 23, 2026

A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of…

CVSS 2.9 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-45187

Published May 19, 2026

Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixe…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-8786

Published May 18, 2026

A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-8747

Published May 17, 2026

A weakness has been identified in Z-BlogPHP 1.7.4.3430. This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approval…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8743

Published May 17, 2026

A vulnerability was found in Open5GS up to 2.7.6. This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME. Performing a mani…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
31.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-45365

Published May 15, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an internal-only bypass_filter parameter is exposed on the /ope…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45345

Published May 15, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.5.7, a user can modify another user's model even if its visibility is…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45371

Published May 14, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs. POST /api/graph/getGrap…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-45147

Published May 14, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-44504

Published May 14, 2026

Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a cross-tenant IDOR. Any authent…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-9988

Published May 13, 2026

The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_advertiser AJAX action in all versions up to, and includi…

CVSS 4.3 · Medium

CVE-2026-34656

Published May 12, 2026

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43515

Published May 12, 2026

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-43983

Published May 12, 2026

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) va…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43912

Published May 11, 2026

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42876

Published May 11, 2026

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.1, a user who only has permission t…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
18.9
Showing 176-200 of 1,432 CVEsPage 8 of 58