Skip to main content

CWE archive

CWE-94 CVEs

Programmatic archive

6,671 CVEs tagged with CWE-941,962 Critical, 2,225 High, 1,606 Medium, 877 Low, 1 Unrated.

CVE-2026-13554

Published Jun 29, 2026

A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/cont…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13536

Published Jun 29, 2026

A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x. The manipulation of the argument sn leads to cross site scr…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
24.4

CVE-2026-13504

Published Jun 28, 2026

A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Su…

CVSS 2.0 · Low
evidence mentions
6
Buzz score
31.0

CVE-2026-13500

Published Jun 28, 2026

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Gramm…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
24.4

CVE-2026-13499

Published Jun 28, 2026

A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-53576

Published Jun 26, 2026

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request wh…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-55441

Published Jun 26, 2026

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions) through trust_check, but tas…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-33646

Published Jun 26, 2026

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the e…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-57315

Published Jun 26, 2026

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-7958

Published Jun 26, 2026

A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artif…

CVSS 7.1 · High

CVE-2026-50741

Published Jun 26, 2026

Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwis…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-55413

Published Jun 25, 2026

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated user with…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-57456

Published Jun 25, 2026

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes…

CVSS 8.4 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-55895

Published Jun 25, 2026

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/…

CVSS 5.7 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-56049

Published Jun 25, 2026

Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-54823

Published Jun 25, 2026

Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-1606

Published Jun 25, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-55570

Published Jun 24, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are serialize…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44016

Published Jun 24, 2026

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0, < 2.91.0, if the HTML backen…

CVSS 8.2 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-12242

Published Jun 24, 2026

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' attribute of the adrotate shortc…

CVSS 8.8 · High
evidence mentions
12
Buzz score
40.6

CVE-2026-53753

Published Jun 23, 2026

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-48519

Published Jun 23, 2026

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulne…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44959

Published Jun 23, 2026

A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-34916

Published Jun 23, 2026

A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject m…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-12866

Published Jun 23, 2026

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions th…

CVSS 9.2 · Critical
evidence mentions
4
Buzz score
22.6
Showing 151-175 of 6,671 CVEsPage 7 of 267