Skip to main content

CWE archive

CWE-843 CVEs

Programmatic archive

864 CVEs tagged with CWE-843106 Critical, 573 High, 159 Medium, 26 Low, 0 Unrated.

CVE-2026-45635

Published Jun 9, 2026

Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.

CVSS 8.1 · High
evidence mentions
4
Buzz score
25.6

CVE-2026-8499

Published Jun 9, 2026

The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1.2.9. This is due to the `help…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2026-11463

Published Jun 7, 2026

A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of the component Shared Pointer Handler. Executing a manipulation can lead to type co…

CVSS 2.9 · Low
evidence mentions
9
Buzz score
37.5

CVE-2026-11052

Published Jun 4, 2026

Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-10955

Published Jun 4, 2026

Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (C…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-45702

Published Jun 3, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in versi…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-9334

Published Jun 3, 2026

Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys int…

CVSS 7.3 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-10702

Published Jun 2, 2026

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

CVSS 4.3 · Medium
evidence mentions
6
Buzz score
39.0
Vendor/product tagsBeta · best-effort

CVE-2026-44640

Published May 29, 2026

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_quic_conn* during dialing, but read as ex_quic_conn* during…

CVSS 4.5 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-44325

Published May 27, 2026

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type-confusion bug fami…

CVSS 7.5 · High
evidence mentions
4
Buzz score
25.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-44728

Published May 26, 2026

Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attack…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 76-100 of 864 CVEsPage 4 of 35