CWE-273
CVEs classified under CWE-273, newest first.
5 CVEsRSS
CVE-2026-80047High· 7.8Hugging Face Transformers library writes remote code to disk prior to consent check
A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and <= 5.8.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches …
CVE-2026-54552High· 7.9sh provides Python process launching
sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. When sh runs from an elevated process and launches a command with _uid set to an unprivi…
CVE-2026-35370Medium· 4.4id: groups= computed from real GID instead of effective GID
id: groups= computed from real GID instead of effective GID
CVE-2026-0099High· 7.8In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code
In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges n…
CVE-2023-52433High· 7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this transaction might expired before such transaction ends
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this transaction might expired before such transaction ends. Skip sync GC …