Skip to main content

CWE archive

CWE-674 CVEs

Programmatic archive

504 CVEs tagged with CWE-6747 Critical, 228 High, 239 Medium, 30 Low, 0 Unrated.

CVE-2026-4224

Published Mar 16, 2026

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS 6.0 · Medium
evidence mentions
11
Buzz score
41.4
Vendor/product tagsBeta · best-effort

CVE-2026-31899

Published Mar 13, 2026

CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of service via recursive <use> element amplification in cairosvg…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-32141

Published Mar 12, 2026

flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a cra…

CVSS 7.5 · High
evidence mentions
14
Buzz score
40.1
Vendor/product tagsBeta · best-effort

CVE-2026-1069

Published Mar 11, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sendi…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-30980

Published Mar 10, 2026

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is a stack overflow in CIccBasicStructFactory::CreateStruct()…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-29076

Published Mar 7, 2026

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib uses std::regex (libstdc++) to parse RFC 5987 encoded filena…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25048

Published Mar 5, 2026

xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32, the multi-level nested syntax caused a segmentation fault…

CVSS 8.7 · High
evidence mentions
10
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2026-3520

Published Mar 4, 2026

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by send…

CVSS 8.7 · High
evidence mentions
9
Buzz score
39.0
Vendor/product tagsBeta · best-effort

CVE-2026-3388

Published Mar 1, 2026

A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation re…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
33.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-3385

Published Mar 1, 2026

A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recu…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
35.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-3384

Published Mar 1, 2026

A security vulnerability has been detected in ChaiScript up to 6.1.0. This impacts the function chaiscript::eval::AST_Node_Impl::eval/chaiscript::eval::Function_Push_Pop of the fi…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2026-25971

Published Feb 24, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for circular referen…

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-2887

Published Feb 21, 2026

A security vulnerability has been detected in aardappel lobster up to 2025.4. This impacts the function lobster::TypeName in the library dev/src/lobster/idents.h. Such manipulatio…

CVSS 1.9 · Low
evidence mentions
9
Buzz score
34.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-27014

Published Feb 19, 2026

NanaZip is an open source file archive Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOffset` chains cause an infinite loop, and deeply nested direc…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-65519

Published Feb 18, 2026

mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and XML file import processing. The application fails to validate nesting depth during p…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-2641

Published Feb 18, 2026

A weakness has been identified in universal-ctags ctags up to 6.2.1. The affected element is the function parseExpression/parseExprList of the file parsers/v.c of the component V…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2025-70957

Published Feb 13, 2026

A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises from the handling of external arguments passed to locally e…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9

CVE-2025-70955

Published Feb 13, 2026

A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10. The vulnerability stems from the improper handling of vmstate and continuation jump…

CVSS 7.5 · High
evidence mentions
4
Buzz score
24.1

CVE-2026-1849

Published Feb 10, 2026

MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the serve…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23066

Published Feb 4, 2026

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recvmsg() unconditional requeue If rxrpc_recvmsg() fails because MSG_DONTWAIT was specified but th…

CVSS 7.8 · High
evidence mentions
7
Buzz score
25.8
Vendor/product tagsBeta · best-effort

CVE-2025-36001

Published Jan 30, 2026

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service using a specia…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22260

Published Jan 27, 2026

Suricata is a network IDS, IPS and NSM engine. Starting in version 8.0.0 and prior to version 8.0.3, Suricata can crash with a stack overflow. Version 8.0.3 patches the issue. As…

CVSS 7.5 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-55095

Published Jan 27, 2026

The function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters an extended partition entry in the partit…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-50537

Published Jan 26, 2026

Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exploit is triggered via the Rule…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-24401

Published Jan 24, 2026

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segmen…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 151-175 of 504 CVEsPage 7 of 21