Skip to main content

CWE archive

CWE-829 CVEs

Programmatic archive

289 CVEs tagged with CWE-82959 Critical, 156 High, 65 Medium, 8 Low, 1 Unrated.

CVE-2025-55305

Published Sep 4, 2025

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 thr…

CVSS 6.1 · Medium

CVE-2025-57729

Published Aug 20, 2025

In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8714

Published Aug 14, 2025

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating sys…

CVSS 8.8 · High

CVE-2025-54135

Published Aug 5, 2025

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it…

CVSS 8.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-36727

Published Jul 25, 2025

Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12.

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54558

Published Jul 25, 2025

OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.

CVSS 4.1 · Medium

CVE-2025-27582

Published Jul 14, 2025

The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within…

CVSS 7.6 · High

CVE-2025-53546

Published Jul 9, 2025

Folo organizes feeds content into one timeline. Using pull_request_target on .github/workflows/auto-fix-lint-format-commit.yml can be exploited by attackers, since untrusted code…

CVSS 9.1 · Critical

CVE-2025-49809

Published Jul 4, 2025

mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules,…

CVSS 7.8 · High

CVE-2025-34074

Published Jul 2, 2025

An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design in the scheduled task functionality. An administrator with a…

CVSS 9.4 · Critical

CVE-2025-34060

Published Jul 1, 2025

A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the /get/image/ endpoint. The appl…

CVSS 10.0 · Critical

CVE-2025-32463

Published Jun 30, 2025

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

CVSS 9.3 · Critical
evidence mentions
8
Buzz score
78.5
KEV listedPublic PoC observed

CVE-2025-36852

Published Jun 10, 2025

A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remote cache (such as those using Amazon S3, Google Cloud Stora…

CVSS 9.4 · Critical

CVE-2025-39507

Published May 16, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core nasa-core allows PHP Local File Inclus…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52976

Published May 1, 2025

Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An at…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20236

Published Apr 16, 2025

A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the a…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-33027

Published Apr 15, 2025

In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affe…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-33026

Published Apr 15, 2025

In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected insta…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45482

Published Mar 25, 2025

An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may allow an authenticated local attacker from a trusted remote…

CVSS 8.5 · High

CVE-2025-27607

Published Mar 7, 2025

Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This oc…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24796

Published Mar 6, 2025

Collabora Online is a collaborative online office suite based on LibreOffice. Macro support is disabled by default in Collabora Online, but can be enabled by an administrator. Col…

CVSS 6.3 · Medium

CVE-2025-27510

Published Mar 4, 2025

conda-forge-metadata provides programatic access to conda-forge's metadata. conda-forge-metadata uses an optional dependency - "conda-oci-mirror" which was neither present on the…

CVSS 9.3 · Critical

CVE-2024-31144

Published Feb 14, 2025

For a brief summary of Xapi terminology, see: https://xapi-project.github.io/xen-api/overview.html#object-model-overview Xapi contains functionality to backup and restore me…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort
Showing 126-150 of 289 CVEsPage 6 of 12