VulnSea

CWE-693

CVEs classified under CWE-693, newest first.

244 CVEsRSS

CVE-2026-55304Medium· 6.7
6d ago

In addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code

In addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed …

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-55302Medium· 6.7
6d ago

In multiple locations, there is a possible permission bypass due to a logic error in the code

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-55359High· 7.8
6d ago

In multiple locations, there is a possible permission bypass due to a logic error in the code

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-56881High· 8.4
6d ago

In enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code

In enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exp…

Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-55366Critical· 9.8
6d ago

In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code

In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for …

Midnightgoogle · androidEPSS 0.36%via NVD
CVE-2026-56941High· 8.4
6d ago

In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code

In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed …

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-56973Medium· 6.7
6d ago

In multiple locations, there is a possible escalation of privilege due to a logic error in the code

In multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-56970High· 8.4
6d ago

In multiple locations, there is a possible permission bypass due to a missing permission check

In multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitat…

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-56982High· 7.8
6d ago

In VPU, there is a possible permission bypass due to a missing permission check

In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-56979Medium· 6.7
6d ago

In multiple locations, there is a possible permission bypass due to a logic error in the code

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-57006Medium· 4.4
6d ago

In acfw_ffa.c, there is a possible secret read due to a logic error in the code

In acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-57012High· 8.4
6d ago

In the Setup Wizard, there is a possible remote package install due to a missing permission check

In the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for explo…

Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2026-58678High· 7.8
6d ago

In Bootloader, there is a possible permission bypass due to a logic error in the code

In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-58704High· 8.8CISA KEV0dayPoC
6d ago

In Cellular Modem, there is a possible permission bypass due to a logic error in the code

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not need…

Abyssalgoogle · androidEPSS 0.21%via NVD
CVE-2026-91949Critical· 9.3
6d ago

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protoco…

MidnightFreeRDP · FreeRDPEPSS 0.45%via NVD
CVE-2026-92019High· 8.1
6d ago

Mitigation bypass in the Remote Settings Client component

Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.17%via NVD
CVE-2026-92018Critical· 9.6⚖ disputed
6d ago

Sandbox escape in the DOM: Core & HTML component

Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.35%via NVD
CVE-2026-92030Medium· 5.4
6d ago

Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component

Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-92039Medium· 6.3
6d ago

Mitigation bypass in the DOM: Notifications component

Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-92038Critical· 9.1
6d ago

Mitigation bypass in the Remote Settings Client component

Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-92041Critical· 9.1⚖ disputed
6d ago

Mitigation bypass in the DOM: Networking component

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-92057Critical· 9.1⚖ disputed
6d ago

Mitigation bypass in the Enterprise Policies component

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.15%via NVD
CVE-2026-92066Critical· 9.8⚖ disputed
6d ago

Sandbox escape in the Profile Backup component

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

MidnightMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-57138Critical· 9.9
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blockl…

MidnightMervinPraison · PraisonAIEPSS 0.39%via NVD
CVE-2026-57137High· 8.8PoC
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped A…

MidnightMervinPraison · PraisonAIEPSS 0.36%via NVD
CVE-2026-57135High· 7.6PoC
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment…

MidnightMervinPraison · PraisonAIEPSS 0.31%via NVD
CVE-2026-57133High· 8.8PoC
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the compl…

MidnightMervinPraison · PraisonAIEPSS 0.44%via NVD
CVE-2026-57136High· 8.8PoC
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExec…

MidnightMervinPraison · PraisonAIEPSS 0.39%via NVD
CVE-2026-53710Critical· 10.0
6d ago

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw geta…

MidnightIBM · mcp-context-forgeEPSS 0.83%via NVD
CVE-2026-47424High· 7.5
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.35%via NVD
CWE-693 vulnerabilities (CVEs) — page 2 · VulnSea