CWE-134

CWE-134 · 6 records · 1 with a public proof-of-concept

Records the NVD classes under CWE-134, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-76722

    Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-o…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.7CVE-2026-84691

    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an ar…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.8CVE-2026-47494public PoC

    NVIDIA GPU Display Driver for Linux contains a vulnerability where a user might be able to cause a format string issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and in…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.6CVE-2026-76729

    A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a …

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-14157

    Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.

    AI risk analysis on Exploit-DB.ai →

  6. UNSCOREDCVE-2026-18461

    Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, from 7.3.0.10 before 7.3.1.6.

    AI risk analysis on Exploit-DB.ai →