VulnSea

CWE-183

CVEs classified under CWE-183, newest first.

14 CVEsRSS

CVE-2026-90808Medium· 6.3PoC
1w ago

A vulnerability was determined in HKUDS nanobot up to 0.2.1

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blackli…

TwilightHKUDS · nanobotEPSS 0.29%via NVD
CVE-2026-54694Critical· 9.6PoC
1w ago

SkillTree is a micro-learning gamification platform

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` b…

AbyssalNationalSecurityAgency · skills-serviceEPSS 0.28%via NVD
CVE-2026-55581High· 8.4
4w ago

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and ch…

Twilightsonirico · github.com/sonirico/mcp-shellEPSS 0.34%via NVD
CVE-2026-67315None
1mo ago

axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules

axios versions 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through configured pr…

SunlitEPSS 0.33%via NVD
CVE-2026-66005Medium· 6.3PoC
2mo ago

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-…

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-…

Twilightjanhq · janEPSS 0.20%via NVD
GHSA-f4gw-2p7v-4548Medium
2mo ago

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

Sunlitaxios · axiosvia GHSA
CVE-2026-16129Medium· 5.3
2mo ago

A vulnerability has been found in princezuda SafestClaw up to 4.2.4

A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction._validate_command of the file src/safestclaw/actions/shell.py of the component Built-in Web Interface. Such manipula…

SunlitEPSS 0.32%via NVD
CVE-2026-8918High· 7.1
3mo ago

A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update …

A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update …

TwilightASUS · Armoury CrateEPSS 0.28%via NVD
CVE-2026-46608High· 7.4
3mo ago

Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)

Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)

Twilightglances · glancesEPSS 0.40%via GHSA
CVE-2026-11525Low· 3.7
3mo ago

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

Sunlitundici · undiciEPSS 0.24%via GHSA
CVE-2026-54316MediumPoC
3mo ago

Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch

Twilightanthropic-ai · @anthropic-ai/claude-codeEPSS 0.52%via GHSA
GHSA-82fg-2r99-h7v6Critical· 10.0
3mo ago

Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

Midnightpicklescan · picklescanvia GHSA
CVE-2026-42043High· 7.2PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to complet…

Midnightaxios · axiosEPSS 0.66%via NVD
CVE-2026-21915Medium· 6.7
5mo ago

A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu acce…

A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu acce…

Sunlitjuniper · virtual_lightweight_collectorEPSS 2.2%via NVD
CWE-183 vulnerabilities (CVEs) · VulnSea