VulnSea

CWE-184

CVEs classified under CWE-184, newest first.

89 CVEsRSS

CVE-2026-14534High· 8.8
2mo ago

Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py)

Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denyli…

▾ TwilightEPSS 0.59%via NVD
GHSA-j472-gf56-x589High
2mo ago

OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks

OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-49869Critical· 10.0CISA KEVPoC
3mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…

▾ Hadalkestra · kestraEPSS 2.1%via NVD
GHSA-g7vj-qw6x-g3p8Critical· 9.8
3mo ago

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

▾ Midnightpicklescan · picklescanvia GHSA
CVE-2026-54512High· 8.1PoC
3mo ago

jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass the PolymorphicTypeValidator (PTV) when polymorphic typing is enabled and a type identifier contains generic parameters. By crafting a malicious ty…

▾ MidnightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 1.00%via CSAF
CVE-2026-54513High· 8.1
3mo ago

jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513)

A flaw was found in jackson-databind, a library used for processing data. This vulnerability allows an attacker to bypass security controls designed to validate data types. By sending specially crafted input, an attacker can force the syst…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 1.2%via CSAF
GHSA-fh2f-24rh-r2vqHigh
3mo ago

Duplicate Advisory: Picklescan missing detection when calling built-in python library function timeit.timeit()

Duplicate Advisory: Picklescan missing detection when calling built-in python library function timeit.timeit()

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-8678-w3jw-xfc2Low· 2.6
3mo ago

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247

▾ Sunlitnokogiri · nokogirivia GHSA
CVE-2026-53864High· 8.1
3mo ago

OpenClaw: Host environment sanitizer missed two Node.js control variables

OpenClaw: Host environment sanitizer missed two Node.js control variables

▾ Twilightopenclaw · openclawEPSS 0.43%via GHSA
CVE-2026-53866High· 8.1
3mo ago

OpenClaw: Shell inline-command parsing could miss an allowlist check

OpenClaw: Shell inline-command parsing could miss an allowlist check

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
GHSA-vmmj-pfw7-fjwpCritical· 9.9
3mo ago

npm PraisonAI codeMode sandbox escape via Function constructor

npm PraisonAI codeMode sandbox escape via Function constructor

▾ Midnightpraisonai · praisonaivia GHSA
CVE-2026-53861Medium· 6.6
3mo ago

OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags

OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags

▾ Sunlitopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-53848Low· 4.3
3mo ago

OpenClaw: Exec allowlist could miss side effects from transparent command wrappers

OpenClaw: Exec allowlist could miss side effects from transparent command wrappers

▾ Sunlitopenclaw · openclawEPSS 0.31%via GHSA
CVE-2026-55743Critical· 9.6
3mo ago

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.

▾ MidnightEPSS 0.57%via NVD
GHSA-6v84-v468-3c7fCritical· 9.8
3mo ago

Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs

Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-7f79-rvx6-vxc4Critical· 9.8
3mo ago

Duplicate Advisory: Picklescan does not block ctypes

Duplicate Advisory: Picklescan does not block ctypes

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-4mpj-78p6-rj59Critical· 9.8
3mo ago

Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass

Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-8rfp-98v4-mmr6Low· 0.0
3mo ago

Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output

Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output

▾ Sunlitbleach · bleachvia OSV
GHSA-wrr6-p5r6-474mLow· 4.3
3mo ago

Duplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers

Duplicate Advisory: Exec allowlist could miss side effects from transparent command wrappers

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-27pq-2ph8-8x25High· 8.1
3mo ago

Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks

Duplicate Advisory: Shell positional parameters could weaken strict inline-eval checks

▾ Twilightopenclaw · openclawvia GHSA
GHSA-g796-jqmx-wf9qMedium· 6.6
3mo ago

Duplicate Advisory: macOS Swift exec allowlist missed combined POSIX inline flags

Duplicate Advisory: macOS Swift exec allowlist missed combined POSIX inline flags

▾ Sunlitopenclaw · openclawvia GHSA
GHSA-vr6h-vxqj-3pjxHigh· 8.1
3mo ago

Duplicate Advisory: Host environment sanitizer missed two Node.js control variables

Duplicate Advisory: Host environment sanitizer missed two Node.js control variables

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-48736Medium
3mo ago

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

▾ Sunlitsymfony · symfony/http-clientEPSS 0.57%via GHSA
CVE-2026-54090High
3mo ago

File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection

File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.44%via GHSA
CVE-2026-44115High· 8.8
4mo ago

OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist

OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to ex…

▾ TwilightOpenClaw · OpenClawEPSS 0.61%via CVEORG
CVE-2026-44114High· 7.8
4mo ago

OpenClaw < 2026.4.20 - Environment Variable Namespace Collision via Workspace dotenv

OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dotenv files, allowing attackers to override critical runtime variables. Malicious workspaces can set variables like OPE…

▾ TwilightOpenClaw · OpenClawEPSS 0.19%via CVEORG
CVE-2026-56315Critical· 9.8
6mo ago

PickleScan has multiple stdlib modules with direct RCE not in blocklist

PickleScan has multiple stdlib modules with direct RCE not in blocklist

▾ Midnightpicklescan · picklescanEPSS 1.1%via OSV
CVE-2025-71351Medium
1y ago

Picklescan missing detection when calling built-in python library function timeit.timeit()

Picklescan missing detection when calling built-in python library function timeit.timeit()

▾ Sunlitpicklescan · picklescanEPSS 0.71%via OSV
CVE-2024-30103High· 8.8
2y ago

Microsoft Outlook Remote Code Execution Vulnerability

Microsoft Outlook Remote Code Execution Vulnerability

▾ Twilightmicrosoft · 365_appsEPSS 3.4%via NVD
CWE-184 vulnerabilities (CVEs) — page 3 · VulnSea