Threats Tagged 'cwe-27'
View all threats tagged with 'cwe-27'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-27'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-62391 is a path traversal vulnerability in Apache Kyuubi affecting versions from 1.6.0 up to but not including 1.12.0. The issue arises because the security fix for a previous vulnerability (CVE-2025-66518) is incomplete, allowing clients with access to the Kyuubi Server via frontend protocols to bypass server-side directory allowlist restrictions using unprefixed Spark config aliases. This vulnerability has a high severity score of 8.1 and impacts confidentiality and integrity without affecting availability. Join the discussion | CVE Database V5 | 07/31/2026, 09:58:15 UTC Added: 07/31/2026, 10:22:52 UTC |
An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2. Join the discussion | CVE Database V5 | 03/05/2026, 16:27:30 UTC Added: 03/05/2026, 18:21:08 UTC |
0 Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue. Join the discussion | CVE Database V5 | 01/05/2026, 08:46:27 UTC Added: 01/05/2026, 08:59:31 UTC |
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. Join the discussion | CVE Database V5 | 10/11/2025, 08:52:23 UTC Added: 10/11/2025, 08:56:17 UTC |
Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical Systems Industry Trade Inc. Yordam Katalog allows Path Traversal. This issue affects Yordam Katalog: before 21.7. Join the discussion | CVE Database V5 | 09/25/2025, 09:18:44 UTC Added: 09/25/2025, 09:30:23 UTC |
Showing 1 to 5 of 5 results