VulnSea

CWE-470

CVEs classified under CWE-470, newest first.

45 CVEsRSS

CVE-2026-78030Critical· 9.8
2d ago

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a mo…

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a mo…

MidnightEPSS 0.73%via NVD
CVE-2026-93762Critical· 9.8
3d ago

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain un…

MidnightMongoDB Inc. · MongoidEPSS 0.34%via NVD
CVE-2026-93765Critical· 9.1
3d ago

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended inte…

MidnightMongoDB Inc. · MongoidEPSS 0.29%via NVD
CVE-2026-10853High· 7.5
3d ago

IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.

IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.

TwilightIBM · MQEPSS 0.36%via NVD
CVE-2026-65608High· 8.8
4d ago

Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

Twilightgetgrav · getgrav/gravEPSS 0.85%via GHSA
CVE-2026-69088High· 8.1
4d ago

Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Twilightgetgrav · getgrav/gravEPSS 0.23%via GHSA
CVE-2026-66269High· 7.3
4d ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potential…

TwilightDell · Dell OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.37%via NVD
CVE-2026-61599High· 8.8
5d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling …

Twilightdjust-org · djustEPSS 0.38%via NVD
CVE-2026-76825High· 8.4
5d ago

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed…

Twilightzopefoundation · RestrictedPythonEPSS 0.57%via NVD
CVE-2026-92126High· 8.5
5d ago

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, includin…

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrategy member names an arbitrary class, allowing attackers with permission to define and run sandboxed scripts, includin…

Twilightjenkins · script_securityEPSS 0.20%via NVD
CVE-2026-86792High· 8.8
5d ago

Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka …

Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka …

Twilightapache · apache-airflow-providers-apache-kafkaEPSS 1.2%via NVD
CVE-2026-62379Critical· 9.8
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUti…

MidnightOpenIdentityPlatform · OpenAMEPSS 0.65%via NVD
CVE-2026-79987High· 8.8
1w ago

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

Twilightcraftcms · craftcms/cmsEPSS 0.36%via NVD
CVE-2026-41871Critical· 9.8
1w ago

Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)

Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are re…

MidnightApache Software Foundation · Apache NutchEPSS 0.78%via CVEORG
CVE-2026-41870High· 8.8
1w ago

Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)

Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in…

TwilightApache Software Foundation · Apache NutchEPSS 0.69%via CVEORG
CVE-2026-58400Critical· 9.1
2w ago

GeoNetwork is a catalog application to manage spatially referenced resources

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) a…

Midnightgeonetwork · core-geonetworkEPSS 1.2%via NVD
CVE-2026-19032Medium· 5.3
2w ago

jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme

jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(…

SunlitEPSS 0.46%via NVD
CVE-2026-82078Critical· 9.4CISA KEVPoC
3w ago

PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against …

HadalPaperCut · PaperCut MF/NGEPSS 3.6%via CVEORG
CVE-2026-55559Critical· 9.8
3w ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templat…

Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.55%via NVD
CVE-2026-54614Medium· 4.3
3w ago

DebugKit provides a debugging toolbar for CakePHP applications

DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in findPreview and passe…

Sunlitcakephp · cakephp/debug_kitEPSS 0.31%via NVD
CVE-2026-68508High· 7.8
1mo ago

Hydra is a framework for elegantly configuring complex applications

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instanti…

Twilighthydra-core · hydra-coreEPSS 0.25%via NVD
CVE-2026-55107Critical· 10.0
1mo ago

kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)

kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)

Midnightkobako · kobakovia GHSA
CVE-2026-63337High
1mo ago

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted syst…

Twilightrabbitmq · com.rabbitmq:amqp-clientEPSS 0.32%via NVD
CVE-2026-55153High· 7.1
1mo ago

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"

Twilightmchange · com.mchange:mchange-commons-javaEPSS 0.19%via GHSA
CVE-2026-19135Medium· 5.4
1mo ago

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary J…

SunlitEPSS 0.17%via NVD
CVE-2022-4993Critical· 9.1
1mo ago

HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notatio…

HTML::FormHandler versions before 0.410000 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notatio…

MidnightEPSS 0.49%via NVD
CVE-2026-17593None
1mo ago

An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configura…

An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configura…

SunlitEPSS 0.36%via NVD
CVE-2026-64663Medium· 6.5
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into Antlers templates could result in the loss of content and assets, on sites whose templa…

Sunlitstatamic · statamic/cmsEPSS 0.30%via NVD
CVE-2026-61536High· 7.5
1mo ago

Banks generates meaningful LLM prompts using a simple template language

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through impo…

TwilightEPSS 0.30%via NVD
GHSA-pp9r-ppc4-25w4High· 8.8
2mo ago

Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

Duplicate Advisory: Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation

Twilightgetgrav · getgrav/gravvia GHSA
CWE-470 vulnerabilities (CVEs) · VulnSea