Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, both ctypes and pydoc modules aren
Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe_imports() method in Fic
PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PyS
PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The
OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dot
OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media proc
OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsistent environment varia
Xibo is an open source digital signage platform with a web content management system and Windows display player software
IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is on
Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenbe
The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattende
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path s
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation
OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always
OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows auth
OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that allows a
OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges.
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passe
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/read
OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provide
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shar
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source file
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.
OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust
October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identifie
OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined
OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec
ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementa
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansio
FastGPT is an AI Agent building platform. In 4.14.7 and earlier, FastGPT's Python Sandbox (fastgpt-sandbox) includes gua
A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/
A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vuln
Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documen
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/rende
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until
Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible t
Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item
OpenClaw versions prior to commit 8aceaf5 contain a preflight validation bypass vulnerability in shell-bleed protection
OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassi
OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CON
OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execut
OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host e
OpenClaw before 2026.4.8 contains a remote code execution vulnerability caused by missing environment variable denylist
A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction
In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value g
@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header
A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.
Frequently Asked Questions
What is CWE-184?
CWE-184 (CWE-184) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-184?
There are 123 CVE records associated with CWE-184 in our database. Of these, 18 are critical severity, 53 are high severity, and 37 are medium severity.
How can I protect against CWE-184 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-184 using AI-powered security agents.
Detect CWE-184 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-184 vulnerabilities across your infrastructure.
Get Started