VulnSea

CWE-693

CVEs classified under CWE-693, newest first.

276 CVEsRSS

GHSA-jwm3-qcfw-c5ppMedium· 5.0
3mo ago

n8n: Python Code Node AST Validator Bypass

n8n: Python Code Node AST Validator Bypass

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-49459Medium· 6.1
3mo ago

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM

▾ Sunlitdompurify · dompurifyEPSS 0.36%via GHSA
CVE-2026-49458Medium· 6.1
3mo ago

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

▾ Sunlitdompurify · dompurifyEPSS 0.40%via GHSA
GHSA-76mc-f452-cxcmMedium· 6.1
3mo ago

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

▾ Sunlitdompurify · dompurifyvia GHSA
GHSA-vxr8-fq34-vvx9Low
3mo ago

DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output

DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output

▾ Sunlitdompurify · dompurifyvia GHSA
CVE-2026-48033High
3mo ago

@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name

@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name

▾ Twilighthulumi · @hulumi/policiesEPSS 0.48%via GHSA
CVE-2026-48037Medium
3mo ago

@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture

@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture

▾ Sunlithulumi · @hulumi/baselineEPSS 0.45%via GHSA
CVE-2026-45656High· 7.8
3mo ago

UEFI Secure Boot Security Feature Bypass Vulnerability

Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.33%via CVEORG
CVE-2026-45655Medium· 5.3
3mo ago

Windows BitLocker Security Feature Bypass Vulnerability

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-45588High· 7.9
3mo ago

Secure Boot Security Feature Bypass Vulnerability

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2026-48568High· 7.9
3mo ago

Secure Boot Security Feature Bypass Vulnerability

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2026-48570High· 7.9
3mo ago

Secure Boot Security Feature Bypass Vulnerability

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2026-48575High· 7.9
3mo ago

Secure Boot Security Feature Bypass Vulnerability

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2026-45459Low· 3.3
3mo ago

Microsoft Excel Security Feature Bypass Vulnerability

Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.

▾ SunlitMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.47%via CVEORG
CVE-2026-45595Medium· 5.4
3mo ago

Windows Mark of the Web Security Feature Bypass Vulnerability

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.47%via CVEORG
CVE-2026-47656High· 7.9
3mo ago

Windows Boot Manager Security Feature Bypass Vulnerability

Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.35%via CVEORG
CVE-2026-42890Medium
3mo ago

actual Allows Electron to Run As Node

actual Allows Electron to Run As Node

▾ Sunlitactual · actualEPSS 0.18%via GHSA
CVE-2026-0097High· 8.0
3mo ago

In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error

In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges neede…

▾ Twilightgoogle · androidEPSS 0.12%via NVD
CVE-2026-0087High· 7.8
3mo ago

In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code

In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of privilege with no additional execution …

▾ Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-0077High· 7.8
3mo ago

In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code

In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges nee…

▾ Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2026-24425High· 8.8
4mo ago

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and …

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and …

▾ Twilightsymfony · twigEPSS 0.76%via NVD
CVE-2026-8969High· 8.1
4mo ago

Mitigation bypass in the DOM: Security component

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

▾ Twilightmozilla · firefoxEPSS 0.39%via NVD
CVE-2026-8962High· 8.1
4mo ago

Mitigation bypass in the DOM: Security component

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

▾ Twilightmozilla · firefoxEPSS 0.40%via NVD
CVE-2026-28914Medium· 5.5
4mo ago

A logic issue was addressed with improved file handling

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

▾ Sunlitapple · macosEPSS 0.17%via NVD
CVE-2026-24781Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute …

▾ Midnightvm2_project · vm2EPSS 1.2%via NVD
CVE-2026-41316High· 8.1
5mo ago

ERB is a templating system for Ruby

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed v…

▾ TwilightEPSS 1.3%via NVD
CVE-2026-32202Medium· 4.3CISA KEVPoC
5mo ago

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 4.9%via NVD
CVE-2026-32225High· 8.8
5mo ago

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.82%via NVD
CVE-2026-5911Medium· 4.3
5mo ago

Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crafted HTML page

Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-5903Medium· 6.5
5mo ago

Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page

Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severit…

▾ Sunlitgoogle · chromeEPSS 0.33%via NVD
CWE-693 vulnerabilities (CVEs) — page 8 · VulnSea