Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,497 CVEs tagged with CWE-285128 Critical, 402 High, 665 Medium, 302 Low, 0 Unrated.

CVE-2026-11462

Published Jun 7, 2026

A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeControl…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-11461

Published Jun 7, 2026

A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume En…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-11441

Published Jun 6, 2026

A vulnerability was identified in theonedev onedev up to 15.0.5. This vulnerability affects the function canAccessIssue of the file /issues/ of the component Pull Request Handler.…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-11440

Published Jun 6, 2026

A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/{projectId}/default-branch of the component REST API. This…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-11439

Published Jun 6, 2026

A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the file /projects/ of the component Parent Project Handler. Th…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-11438

Published Jun 6, 2026

A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
27.5

CVE-2026-10580

Published Jun 5, 2026

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
35.5

CVE-2026-11336

Published Jun 5, 2026

A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected is an unknown f…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10876

Published Jun 5, 2026

A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
27.5

CVE-2026-48579

Published Jun 4, 2026

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-41522

Published Jun 4, 2026

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to version 2.4.28, DFIR-IRIS exposes an optional GraphQL e…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-10693

Published Jun 3, 2026

A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Admini…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
27.5

CVE-2026-33398

Published Jun 2, 2026

NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only checks whether the caller is logged in, then reads a post b…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-41115

Published Jun 2, 2026

An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GR…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-10294

Published Jun 1, 2026

A vulnerability has been found in PackageKit up to 1.3.5. Affected is the function g_file_test of the file src/pk-transaction.c of the component API. Such manipulation of the argu…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10285

Published Jun 1, 2026

A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-10284

Published Jun 1, 2026

A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Reso…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-45275

Published Jun 1, 2026

Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without shar…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-10282

Published Jun 1, 2026

A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the file app/Http/Controllers/DocumentsController.php. Such manip…

CVSS 5.3 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-0072

Published Jun 1, 2026

In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with n…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-10272

Published Jun 1, 2026

A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown function of the file admin/dele…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-10269

Published Jun 1, 2026

A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardGuard.js of the component HTTP…

CVSS 5.3 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-46605

Published Jun 1, 2026

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. Th…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-40963

Published Jun 1, 2026

The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags…

CVSS 3.1 · Low
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-10236

Published Jun 1, 2026

A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save of the compo…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
27.5
Showing 201-225 of 1,497 CVEsPage 9 of 60