Skip to main content

CWE archive

CWE-74 CVEs

Programmatic archive

4,975 CVEs tagged with CWE-74242 Critical, 531 High, 3,008 Medium, 1,193 Low, 1 Unrated.

CVE-2026-20220

Published Jun 17, 2026

A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-11311

Published Jun 17, 2026

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric.…

CVSS 8.6 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-12223

Published Jun 15, 2026

A vulnerability was identified in Yealink SIP-T46U 108.86.0.118. Affected by this vulnerability is the function mod_webd.TFTPUploadIperf of the file /api/inner/tftpuploadiperf of…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
27.9

CVE-2026-12219

Published Jun 15, 2026

A flaw has been found in Yealink SIP-T46U 108.86.0.118. The impacted element is the function mod_diagnose.CommandShellByType of the file /api/diagnosis/start of the component Web…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
27.9

CVE-2026-12206

Published Jun 15, 2026

A vulnerability was identified in Grit42 Grit up to 0.11.0. This issue affects the function Grit::Assays::DataTableEntity of the file modules/assays/backend/app/models/grit/assays…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-12197

Published Jun 15, 2026

A security flaw has been discovered in Ruijie EG105G-P 2.340. The impacted element is the function nslookup of the file /cgi-bin/luci/api/diagnose of the component JSON-RPC Diagno…

CVSS 7.3 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-12188

Published Jun 14, 2026

A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app/controllers/concerns/grit/core/…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-12187

Published Jun 14, 2026

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of t…

CVSS 7.4 · High
evidence mentions
6
Buzz score
31.0

CVE-2026-12186

Published Jun 14, 2026

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Serv…

CVSS 7.4 · High
evidence mentions
6
Buzz score
31.0

CVE-2026-12175

Published Jun 13, 2026

A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performin…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-12131

Published Jun 12, 2026

A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \application\controllers\Payroll.php…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-47162

Published Jun 11, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/p…

CVSS 7.3 · High
evidence mentions
7
Buzz score
38.8
Vendor/product tagsBeta · best-effort

CVE-2026-11859

Published Jun 10, 2026

An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails cli…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-46546

Published Jun 10, 2026

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafte…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47634

Published Jun 9, 2026

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing…

CVSS 7.3 · High
evidence mentions
5
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-42835

Published Jun 9, 2026

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose informa…

CVSS 8.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-8795

Published Jun 9, 2026

A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in client_info.json inside a co…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-11585

Published Jun 8, 2026

A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This m…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-11584

Published Jun 8, 2026

A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the file /attendance-php/Admin/createClass.php?action=edit. Th…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-11583

Published Jun 8, 2026

A vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function of the file /attendance-php/Admin/createClass.php. The manip…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-11582

Published Jun 8, 2026

A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipul…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
31.0

CVE-2026-11559

Published Jun 8, 2026

A vulnerability was detected in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account.php. The manipulation of the argument ID results in sql in…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-11558

Published Jun 8, 2026

A security vulnerability has been detected in CodeAstro Payroll System 1.0. The impacted element is an unknown function of the file /home_salary.php. The manipulation of the argum…

CVSS 2.1 · Low
evidence mentions
8
Buzz score
33.5

CVE-2026-11531

Published Jun 8, 2026

A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This impacts an unknown function of the file admin/admin_…

CVSS 5.5 · Medium
evidence mentions
6
Buzz score
26.0
Showing 176-200 of 4,975 CVEsPage 8 of 199