VulnSea

CWE-116

CVEs classified under CWE-116, newest first.

109 CVEsRSS

GHSA-hc76-7mpc-qjqhMedium· 5.7
2mo ago

ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797

ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-pppj-hq3g-57pjHigh
2mo ago

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

▾ Twilightjupyterlab · jupyterlabvia GHSA
CVE-2026-64647Medium
2mo ago

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences

▾ Sunlitnext · nextEPSS 0.32%via GHSA
CVE-2026-59895Medium· 6.1
2mo ago

Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility

Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility

▾ Sunlithono · honoEPSS 0.33%via GHSA
CVE-2026-59727Low
2mo ago

Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

▾ Sunlitastro · astroEPSS 0.54%via GHSA
CVE-2026-15809High· 7.8
2mo ago

A flaw was found in CRI-O

A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME e…

▾ TwilightRed Hat · cri-oEPSS 0.18%via NVD
CVE-2026-50659Medium· 6.5
2mo ago

.NET Spoofing Vulnerability

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · .NET 10.0EPSS 0.74%via CVEORG
CVE-2026-45710Low· 3.5
2mo ago

FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`

FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`

▾ Sunlitfacturascripts · facturascripts/facturascriptsvia GHSA
CVE-2026-49844Medium· 6.3PoC
2mo ago

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON

Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.…

▾ TwilightApache Software Foundation · org.apache.logging.log4j:log4j-apiEPSS 0.81%via NVD
CVE-2026-55659High· 7.7
2mo ago

Grist is spreadsheet software using Python as its formula language

Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled values into the page and into inline scripts without fully escaping them, allowing cross-si…

▾ TwilightEPSS 0.36%via NVD
GHSA-cwv4-h3j5-w3cfLow· 3.7
2mo ago

rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path

rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path

▾ Sunlitrama · ramavia GHSA
CVE-2026-54893Low· 2.1
2mo ago

URL path injection in the Microsoft Graph adapter of Swoosh

URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API request URL by interpolating the sender's email address into the URL path (/users/{from}/sendMail) without percent-encodi…

▾ Sunlitswoosh · swooshEPSS 0.20%via NVD
CVE-2026-35346Low· 3.3
2mo ago

comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output

comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output

▾ Sunlituu_comm · uu_commEPSS 0.17%via GHSA
CVE-2026-35366Medium· 4.4
2mo ago

printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)

printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)

▾ Sunlituu_printenv · uu_printenvEPSS 0.19%via GHSA
GHSA-jf6w-2mvx-633jMedium· 6.1
3mo ago

justhtml: to_markdown() code-span blank-line breakout enables XSS

justhtml: to_markdown() code-span blank-line breakout enables XSS

▾ Sunlitjusthtml · justhtmlvia GHSA
GHSA-v772-658q-978pLow
3mo ago

Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c

Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-56379High· 8.1
3mo ago

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector G…

▾ Twilightimagemagick · imagemagickEPSS 1.6%via NVD
CVE-2026-44913Medium· 7.2
3mo ago

Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL

Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL

▾ Sunlitapache · org.apache.nifi:nifi-cdc-mysql-processorsEPSS 0.65%via GHSA
CVE-2026-12048Critical· 9.3
3mo ago

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside E…

▾ Midnightpgadmin · pgadmin_4EPSS 0.27%via NVD
CVE-2026-12047Low· 3.5
3mo ago

HTML injection in pgAdmin 4's cloud deployment module

HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propagated AWS / Azure / Google SDK exception…

▾ Sunlitpgadmin · pgadmin_4EPSS 0.22%via NVD
GHSA-9wxg-vf3r-56hcLow· 3.3
3mo ago

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

▾ Sunlitopenzeppelin · @openzeppelin/wizardvia GHSA
GHSA-38x9-25wx-7fg2High
3mo ago

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

▾ Twilighthttps: · https://github.com/dadrus/heimdallvia GHSA
GHSA-crmm-hgp2-wgrpMedium· 4.2
3mo ago

Laravel Framework: Temporary Signed URL Path Confusion

Laravel Framework: Temporary Signed URL Path Confusion

▾ Sunlitlaravel · laravel/frameworkvia GHSA
CVE-2026-54013High· 7.6
3mo ago

Open WebUI: Stored XSS to Account Takeover via Model Profile Images

Open WebUI: Stored XSS to Account Takeover via Model Profile Images

▾ Twilightopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-54287Medium· 5.3
3mo ago

hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

▾ Sunlithono · honoEPSS 0.31%via GHSA
CVE-2026-52846Medium· 4.2
3mo ago

Caddy: stripHTML template function bypass

Caddy: stripHTML template function bypass

▾ Sunlitcaddyserver · github.com/caddyserver/caddy/v2EPSS 0.25%via GHSA
CVE-2026-54133Critical· 9.8
3mo ago

jmespath.php: jmespath.php has CompilerRuntime code injection via unescaped function names (CVE-2026-54133)

A flaw was found in jmespath.php, a library for processing JSON documents in PHP applications. This vulnerability allows a remote attacker to execute arbitrary code by crafting a malicious JMESPath expression. The `JmesPath\CompilerRuntime…

▾ MidnightRed Hat · mtdowling/jmespath.phpEPSS 0.56%via CSAF
GHSA-6jq6-x4cx-qvcmMedium
3mo ago

Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)

Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)

▾ Sunlitgrumpydictator · grumpydictator/firefly-iiivia GHSA
CVE-2026-44311Medium· 5.4
3mo ago

Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization

Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization

▾ Sunlitfabric · fabricEPSS 0.27%via GHSA
CVE-2026-47768Medium· 5.5
3mo ago

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

▾ Sunlitjuev · github.com/juev/nebula-meshEPSS 0.15%via GHSA
CWE-116 vulnerabilities (CVEs) — page 3 · VulnSea