Skip to main content

CWE archive

CWE-77 CVEs

Programmatic archive

3,705 CVEs tagged with CWE-77968 Critical, 1,508 High, 779 Medium, 448 Low, 2 Unrated.

CVE-2026-11341

Published Jun 5, 2026

A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_va…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-11339

Published Jun 5, 2026

A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument u…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2026-10878

Published Jun 5, 2026

A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument act…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
35.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-45497

Published Jun 4, 2026

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.

CVSS 7.7 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-42824

Published Jun 4, 2026

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-10873

Published Jun 4, 2026

A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Executing a manipulation can lead…

CVSS 7.3 · High
evidence mentions
7
Buzz score
27.3

CVE-2026-10872

Published Jun 4, 2026

A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Performing a manipulation resul…

CVSS 7.3 · High
evidence mentions
6
Buzz score
26.0

CVE-2026-10871

Published Jun 4, 2026

A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation…

CVSS 7.3 · High
evidence mentions
6
Buzz score
26.0

CVE-2026-10870

Published Jun 4, 2026

A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulation causes os command injection…

CVSS 7.3 · High
evidence mentions
6
Buzz score
26.0

CVE-2026-10550

Published Jun 2, 2026

A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java of the component Application Deployment Module. This manip…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-10279

Published Jun 1, 2026

A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the file src/wezterm_executor.ts of the component switch_pane/w…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2024-52011

Published Jun 1, 2026

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `laun…

CVSS 7.5 · High
evidence mentions
6
Buzz score
32.5

CVE-2026-10273

Published Jun 1, 2026

A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a mani…

CVSS 5.5 · Medium
evidence mentions
8
Buzz score
28.5

CVE-2026-10219

Published Jun 1, 2026

A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_fil…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-10214

Published Jun 1, 2026

A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-10182

Published May 31, 2026

A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. Executing a manipulation of th…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-10180

Published May 31, 2026

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads t…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-10166

Published May 31, 2026

A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. Th…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-10127

Published May 30, 2026

A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-45628

Published May 29, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them via ch…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-45663

Published May 29, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an aut…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-10061

Published May 29, 2026

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-10060

Published May 29, 2026

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/ga…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 176-200 of 3,705 CVEsPage 8 of 149