CWE-349

CWE-349 · 5 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-349, highest CVSS first.

  1. HIGH 8.8CVE-2026-95985

    The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message …

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 6.5CVE-2026-19033

    For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.8CVE-2026-78301

    A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose au…

    AI risk analysis on Exploit-DB.ai →

  4. LOW 2.3CVE-2026-62364public PoC

    wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_KEY or --key without a …

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-48100public PoC

    Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory compliant transactions. Prior to version 1.3.0, agg_agg forwards the compacted message stream from its inner proofs into a public messages: [Field; 1000] array, but it never checks that the…

    AI risk analysis on Exploit-DB.ai →