Skip to main content

CWE archive

CWE-345 CVEs

Programmatic archive

649 CVEs tagged with CWE-34583 Critical, 258 High, 266 Medium, 42 Low, 0 Unrated.

CVE-2026-26327

Published Feb 19, 2026

OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as `lanHost`, `tailnetDns`, `gatewayPort`, and `gatewayTlsSha256`. TXT re…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25474

Published Feb 19, 2026

OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP…

CVSS 7.5 · High
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2025-14444

Published Feb 18, 2026

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to payment bypass due to insufficient verification…

CVSS 5.3 · Medium

CVE-2026-26007

Published Feb 10, 2026

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers…

CVSS 8.2 · High
evidence mentions
26
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2026-24775

Published Jan 28, 2026

OpenProject is an open-source, web-based project management software. In the new editor for collaborative documents based on BlockNote, OpenProject maintainers added a custom exte…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-24772

Published Jan 28, 2026

OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents, OpenProject 17.0 introduced a synchronization server. The…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23966

Published Jan 22, 2026

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A private key recovery vulnerability exists in the SM2 decryption logic of…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-1195

Published Jan 20, 2026

A weakness has been identified in MineAdmin 1.x/2.x. This impacts the function refresh of the file /system/refresh of the component JWT Token Handler. This manipulation causes ins…

CVSS 1.3 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-0939

Published Jan 16, 2026

The Rede Itaú for WooCommerce plugin for WordPress is vulnerable to order status manipulation due to insufficient verification of data authenticity in all versions up to, and incl…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
27.9

CVE-2026-22703

Published Jan 10, 2026

Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to successfully verify an artifact even…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-15385

Published Jan 6, 2026

Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects com.Afmobi.Boomplayer: 7.4.63.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-15154

Published Dec 28, 2025

A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66570

Published Dec 5, 2025

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-59700

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker with root access to modify the Recovery Partition (because…

CVSS 3.9 · Low

CVE-2025-66225

Published Nov 29, 2025

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66016

Published Nov 25, 2025

CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. Prior to version 0.6.…

CVSS 9.3 · Critical

CVE-2025-12752

Published Nov 22, 2025

The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions up to, and including, 1.1.7. This is due to the plugin not p…

CVSS 5.3 · Medium

CVE-2025-34337

Published Nov 19, 2025

eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryptio…

CVSS 8.7 · High
evidence mentions
5
Buzz score
30.9

CVE-2025-12080

Published Oct 27, 2025

On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application, the handling of ACTION_SENDTO intents utilizing the sms:, smsto:, mms:, and mmsto: U…

CVSS 6.9 · Medium

CVE-2025-12245

Published Oct 27, 2025

A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 649 CVEsPage 7 of 26