n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Pytho
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun
October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information dis
OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that
CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ
DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate optio
Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create()
OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wr
The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist ca
Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied sys
The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse opti
picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allow
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass stat
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validat
Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runti
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri
Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas
Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versio
Frequently Asked Questions
What is CWE-184?
CWE-184 (CWE-184) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-184?
There are 123 CVE records associated with CWE-184 in our database. Of these, 18 are critical severity, 53 are high severity, and 37 are medium severity.
How can I protect against CWE-184 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-184 using AI-powered security agents.
Detect CWE-184 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-184 vulnerabilities across your infrastructure.
Get Started