OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enab
Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request aut
Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacke
In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOT
KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of th
In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for U
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a
In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel outp
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modobo
In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM p
OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info o
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attrib
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image coul
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no P
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitiz
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Iron
Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redi
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON
In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Clie
In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p em
mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access
Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable fi
Frequently Asked Questions
What is CWE-669?
CWE-669 (CWE-669) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-669?
There are 33 CVE records associated with CWE-669 in our database. Of these, 0 are critical severity, 7 are high severity, and 18 are medium severity.
How can I protect against CWE-669 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-669 using AI-powered security agents.
Detect CWE-669 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-669 vulnerabilities across your infrastructure.
Get Started