Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestr
In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviation
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authentica
PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praiso
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an in
Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder con
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific fl
picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller fun
picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoki
picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level pro
picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _ai
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised sec
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist —
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to
Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limit
OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade
OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrad
ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that al
OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing
Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that
OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment p
OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted
OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and confi
Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanit
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows
Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubp
OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup va
OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport t
OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to pro
Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attac
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when us
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53,
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py
The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP reque
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin
RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input
ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails t
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly
Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Got
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.def
OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict
OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that all
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the
Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat P
Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat P
Frequently Asked Questions
What is CWE-184?
CWE-184 (CWE-184) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-184?
There are 123 CVE records associated with CWE-184 in our database. Of these, 18 are critical severity, 53 are high severity, and 37 are medium severity.
How can I protect against CWE-184 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-184 using AI-powered security agents.
Detect CWE-184 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-184 vulnerabilities across your infrastructure.
Get Started