Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,659 CVEs tagged with CWE-5952 Critical, 735 High, 687 Medium, 185 Low, 0 Unrated.

CVE-2026-54094

Published Jun 25, 2026

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.14, it does not stop the HTT…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50549

Published Jun 25, 2026

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the targe…

CVSS 9.3 · Critical
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-53766

Published Jun 24, 2026

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces work…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53765

Published Jun 24, 2026

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.20.0 until 1.1.0, The chrome-devtools-mcp daemon writes i…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-52811

Published Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)…

CVSS 9.0 · Critical
evidence mentions
4
Buzz score
21.1

CVE-2026-23879

Published Jun 24, 2026

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file wr…

CVSS 8.0 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-35025

Published Jun 24, 2026

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing path…

CVSS 8.6 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-11940

Published Jun 23, 2026

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itsel…

CVSS 7.8 · High
evidence mentions
10
Buzz score
34.0

CVE-2026-56692

Published Jun 23, 2026

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host valid…

CVSS 6.8 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2026-44274

Published Jun 22, 2026

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access cou…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55443

Published Jun 22, 2026

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-56236

Published Jun 21, 2026

Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation. Attackers can create…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-47833

Published Jun 18, 2026

setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to ch…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-12567

Published Jun 17, 2026

The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can…

CVSS 2.2 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-47277

Published Jun 17, 2026

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-store repositories through an una…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-50656

Published Jun 16, 2026

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

CVSS 7.8 · High
evidence mentions
34
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2026-54056

Published Jun 12, 2026

Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary file…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54055

Published Jun 12, 2026

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child pr…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-46293

Published Jun 11, 2026

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45384

Published Jun 10, 2026

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability v…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-53476

Published Jun 10, 2026

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a…

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-11853

Published Jun 10, 2026

Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest files…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-11837

Published Jun 10, 2026

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens f…

CVSS 7.3 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-50511

Published Jun 9, 2026

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 126-150 of 1,659 CVEsPage 6 of 67