VulnSea

CWE-693

CVEs classified under CWE-693, newest first.

276 CVEsRSS

CVE-2026-82474High· 7.8
4w ago

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode. Users permitted to run specific commands can execute denied programs by calling execveat directly or through fexecve…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.13%via NVD
CVE-2026-6876None
1mo ago

ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform

ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the Now Platform, potentially leading to more acc…

▾ SunlitEPSS 0.62%via NVD
CVE-2026-61792High· 7.7
1mo ago

Weblate is a web-based continuous localization platform used to manage software translations

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, w…

▾ TwilightEPSS 0.59%via NVD
CVE-2026-80198High· 7.5
1mo ago

Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys

Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious temp…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-79006Medium· 4.3
1mo ago

chromium-browser: Google Chrome: Web origin policy bypass via crafted network traffic (CVE-2026-79006)

A flaw was found in Google Chrome. This vulnerability, located in the HttpsUpgrades component, allows a remote attacker to bypass the web origin policy. By sending specially crafted network traffic, an attacker could circumvent security re…

▾ SunlitRed Hat · ChromeEPSS 0.25%via CSAF
CVE-2026-47624Medium· 6.0
1mo ago

NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user

NVIDIA DGX Spark contains a vulnerability in UEFI where a Attacker may cause a/an CWE-693 by privileged local user. A successful exploit of this vulnerability may allow an attacker to bypass administrator password protection in UEFi.

▾ Sunlitnvidia · dgx_spark_uefiEPSS 0.18%via NVD
CVE-2026-54073None
1mo ago

VeraCrypt provides disk encryption with strong security based on TrueCrypt

VeraCrypt provides disk encryption with strong security based on TrueCrypt. From 1.26.6 until 1.26.29, file-hosted hidden volume creation forces quick format and the FormatNoFs function in src/Common/Format.c and FormatFat function in sr…

▾ SunlitEPSS 0.12%via NVD
GHSA-8cfw-pcwh-v63wHigh· 8.4
1mo ago

Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)

Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)

▾ Twilightwinter · winter/wn-system-modulevia GHSA
GHSA-9w56-46f6-3qhxMedium· 5.5
1mo ago

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

▾ Sunlitasteval · astevalvia OSV
CVE-2026-76827Medium· 6.8
1mo ago

A flaw was found in search-indexer

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-in…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.53%via NVD
CVE-2026-45733High· 8.3
1mo ago

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-52873Medium· 6.9
1mo ago

Streambert is a cross-platform Electron Desktop App to stream and download video content

Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron session and regis…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-74959Critical· 9.1⚖ disputed
1mo ago

Mitigation bypass in the Storage: Cache API component

Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.48%via NVD
CVE-2026-74957High· 8.1⚖ disputed
1mo ago

Mitigation bypass in the Safe Browsing component

Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.43%via NVD
CVE-2026-65339Medium· 5.0
1mo ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive user information.

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2026-71858None
1mo ago

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC validation applied to UserDefinedCommands and can invoke Scintilla actions and the internal O…

▾ SunlitEPSS 0.12%via NVD
CVE-2026-47686Critical· 9.9
1mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing s…

▾ Midnightvm2 · vm2EPSS 0.58%via NVD
CVE-2026-0293Medium· 6.0
1mo ago

A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma…

A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma…

▾ Sunlitpaloaltonetworks · prisma_access_agentEPSS 0.11%via NVD
CVE-2026-73288Medium· 6.1
1mo ago

RustFS is a distributed object storage system built in Rust

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle…

▾ Sunlitrustfs · rustfsEPSS 0.39%via NVD
CVE-2026-39452High· 7.3
1mo ago

Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege

Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a…

▾ Twilightintel · transfer_learning_toolEPSS 0.33%via NVD
CVE-2026-73217None
1mo ago

Cursor is a code editor built for programming with AI

Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper that the Microsoft…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-73083None
1mo ago

Activepieces is an open source AI workflow automation platform

Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine loads the compiled user module with importFresh(), a wrapper around Node.js require(), before the V8 isolate is applie…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-72781High· 8.8
1mo ago

Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism

Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribut…

▾ TwilightEPSS 0.79%via NVD
CVE-2026-69278High· 7.8
1mo ago

Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

▾ Twilightmicrosoft · visual_studio_codeEPSS 0.32%via NVD
CVE-2026-54981High· 7.8
1mo ago

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.

▾ Twilightmicrosoft · pythonEPSS 0.47%via NVD
CVE-2026-62902Medium· 6.5
1mo ago

.NET Information Disclosure Vulnerability

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · .NET 8.0EPSS 0.87%via CVEORG
CVE-2024-6832Medium· 5.9
1mo ago

The account locking mechanism fails to trigger when secondary user stores are inaccessible

The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repe…

▾ Sunlitwso2 · api_control_planeEPSS 0.41%via NVD
CVE-2026-19152High· 8.3
1mo ago

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security…

▾ Twilightgoogle · chromeEPSS 0.30%via NVD
GHSA-f5wm-88jv-g5hxHigh
1mo ago

Craft CMS: Authenticated RCE through Twig sandbox escape

Craft CMS: Authenticated RCE through Twig sandbox escape

▾ Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-70608High· 7.2
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger s…

▾ Twilightelectron · electronEPSS 0.45%via NVD
CWE-693 vulnerabilities (CVEs) — page 5 · VulnSea