VulnSea

CWE-693

CVEs classified under CWE-693, newest first.

247 CVEsRSS

CVE-2026-57136High· 8.8PoC
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExec…

MidnightMervinPraison · PraisonAIEPSS 0.39%via NVD
CVE-2026-53710Critical· 10.0
6d ago

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw geta…

MidnightIBM · mcp-context-forgeEPSS 0.83%via NVD
CVE-2026-47424High· 7.5
6d ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.35%via NVD
CVE-2026-65369Medium· 5.5
1w ago

A logic issue was addressed with improved state management

A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may bypass Gatekeeper checks.

Sunlitapple · macosEPSS 0.13%via NVD
CVE-2026-65406Medium· 5.5
1w ago

A logic issue was addressed with improved validation

A logic issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to access s…

Sunlitapple · ipadosEPSS 0.13%via NVD
CVE-2026-84570Medium· 4.4
1w ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to bypass Gatekeeper checks.

Sunlitapple · macosEPSS 0.16%via NVD
CVE-2026-43787Medium· 5.9
1w ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to leak sensitive user information.

Sunlitapple · macosEPSS 0.39%via NVD
CVE-2026-28899Medium· 5.5
1w ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may bypass Gatekeeper checks.

Sunlitapple · macosEPSS 0.16%via NVD
CVE-2026-86894High· 7.5
1w ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to break out of its sandbox.

Twilightapple · macosEPSS 0.21%via NVD
CVE-2026-84578High· 8.8
1w ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to break out of its sandbox.

Twilightapple · macosEPSS 0.14%via NVD
CVE-2026-86909Medium· 4.4
1w ago

A logic issue was addressed with improved state management

A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to bypass Gatekeeper checks.

Sunlitapple · macosEPSS 0.11%via NVD
CVE-2026-84559Medium· 5.5
1w ago

A permissions issue was addressed with improved validation

A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A malicious application may be able to access restricted files.

Sunlitapple · macosEPSS 0.12%via NVD
CVE-2026-90957Medium· 5.1
1w ago

Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap images

Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap images. While scripts inside SVG do not execute when the …

SunlitMISP · MISPEPSS 0.23%via NVD
CVE-2026-57120Medium· 6.5PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to resolve dotted fields through C-level att…

TwilightMervinPraison · praisonaiagentsEPSS 0.32%via NVD
CVE-2026-76059High· 8.8
1w ago

IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias t…

IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias t…

Twilightlangflow · langflowEPSS 0.47%via NVD
CVE-2026-45770High· 7.5
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, a Lua rule that registers too many flow variables can corrupt Lua…

Twilightoisf · suricataEPSS 0.34%via NVD
CVE-2026-0306Medium· 5.8
1w ago

A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data

A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Ac…

SunlitPalo Alto Networks · Prisma Access AgentEPSS 0.10%via NVD
CVE-2026-54694Critical· 9.6PoC
1w ago

SkillTree is a micro-learning gamification platform

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` b…

AbyssalNationalSecurityAgency · skills-serviceEPSS 0.28%via NVD
CVE-2026-87808Medium· 4.9PoC
1w ago

SiYuan versions <= 3.8.1 contain an incomplete fix for CVE-2026-32767 (GHSA-j7wh-x834-p3r7)

SiYuan versions <= 3.8.1 contain an incomplete fix for CVE-2026-32767 (GHSA-j7wh-x834-p3r7). The prior fix (commit d5e2d0bc) added an administrator check for SQL mode (method=2) in POST /api/search/fullTextSearchBlock, but the endpoint s…

Twilightsiyuan-note · siyuanEPSS 0.32%via NVD
CVE-2026-79638Medium· 5.3
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access coul…

Sunlitdell · secure_connect_gatewayEPSS 0.20%via NVD
CVE-2026-78552Medium· 6.0
1w ago

The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field

The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of inject…

SunlitOkta · Okta Access GatewayEPSS 0.33%via NVD
CVE-2026-0084High· 7.8
1w ago

In multiple functions of HostEmulationManager.java, there is a possible background activity launch due to a logic error in the code

In multiple functions of HostEmulationManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User in…

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-28612High· 7.8
1w ago

In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code

In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. …

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-28599High· 7.8
1w ago

In addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code

In addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User inte…

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-28594High· 7.8
1w ago

In multiple locations, there is a possible use after free due to a logic error in the code

In multiple locations, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-28584Medium· 5.5
1w ago

In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the code

In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. …

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-28583High· 7.8
1w ago

In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code

In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User…

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-0065High· 7.8
1w ago

In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due to a logic error in the code

In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due to a logic error in the code. This could lead to local escalation of privilege…

Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-28660Low· 3.3
1w ago

In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code

In getAllSessions of multiple files, there is a possible confused deputy due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-28658High· 7.8
1w ago

In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code

In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e…

Twilightgoogle · androidEPSS 0.08%via NVD
CWE-693 vulnerabilities (CVEs) — page 3 · VulnSea