VulnSea

CWE-74

CVEs classified under CWE-74, newest first.

437 CVEsRSS

CVE-2026-15478Medium· 6.3
2mo ago

A flaw has been found in IceHRM up to 35.0.1

A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing a manipulation of the argument employee…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-15477Medium· 6.3
2mo ago

A vulnerability was detected in Bahmni bahmnicore up to 0.93

A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. Performing a manipulation of the argument test resu…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-54159Critical· 10.0
2mo ago

prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE

prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE

▾ Midnightprestashop · prestashop/ps_facetedsearchEPSS 0.75%via GHSA
CVE-2026-0284Critical· 9.9
2mo ago

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to informatio…

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to informatio…

▾ Midnightpaloaltonetworks · pan-osEPSS 0.46%via NVD
CVE-2026-58213High· 7.1
2mo ago

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system

NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.12.9, an MQTT client could include protocol control characters in subscription filters that were later forwarded as N…

▾ Twilightlinuxfoundation · nats-serverEPSS 0.44%via NVD
CVE-2026-55427High· 8.3
2mo ago

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.47%via GHSA
CVE-2026-55615Critical
2mo ago

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

▾ Midnightlangroid · langroidEPSS 0.46%via GHSA
CVE-2026-54771High· 8.1
2mo ago

Langroid: handle_message() executes user-supplied tool JSON without sender verification

Langroid: handle_message() executes user-supplied tool JSON without sender verification

▾ Twilightlangroid · langroidEPSS 0.39%via GHSA
CVE-2026-14619Medium· 6.3
2mo ago

A flaw has been found in itsourcecode Hospital Management System 1.0

A flaw has been found in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /medicine.php. This manipulation of the argument editid causes sql injection. Remote exploitation of t…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-53488High· 8.8
2mo ago

github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin (CVE-2026-53488)

A flaw was found in containerd, an open-source container runtime. The Container Runtime Interface (CRI) plugin, which manages container operations, fails to validate labels propagated from an image configuration to a container. This oversi…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.16%via CSAF
CVE-2026-13542Medium· 6.3
3mo ago

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /doctorprofile.php. The manipulation of the argument doctorname leads to sql injection. It is possible…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13541Medium· 6.3
3mo ago

A weakness has been identified in itsourcecode Hospital Management System 1.0

A weakness has been identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /doctorchangepassword.php. Executing a manipulation of the argument newpassword can lead to sql injection. The at…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13538Medium· 6.3
3mo ago

A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425

A vulnerability was determined in Wavlink WL-NU516U1-A M16U1_V240425. The affected element is the function sub_401D68 of the file /cgi-bin/wireless.cgi of the component POST Parameter Handler. This manipulation of the argument SSID2G2/SS…

▾ SunlitEPSS 2.2%via NVD
CVE-2026-13535Medium· 6.3
3mo ago

A flaw has been found in CodeAstro Human Resource Management System 1.0

A flaw has been found in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function GetFileInfo of the file hrsystem/application/models/Employee_model.php of the component View Endpoint. Executing a manipulat…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13532Medium· 6.3
3mo ago

A weakness has been identified in itsourcecode Hospital Management System 1.0

A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /departmentDoctor.php. This manipulation of the argument deptid causes sql injection. I…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13531Medium· 6.3
3mo ago

A security flaw has been discovered in itsourcecode Hospital Management System 1.0

A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /department.php. The manipulation of the argument editid results in sql injection. The attack may be performe…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13530Medium· 6.3
3mo ago

A vulnerability was identified in itsourcecode Hospital Management System 1.0

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13529Medium· 5.6
3mo ago

A vulnerability was determined in YzmCMS up to 7.5

A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipulation of the argument siteurl can lead to sql injection. The attack can be executed remot…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-13527High· 7.3
3mo ago

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /preview4.php. Such manipulation of the argument course_year_section leads to sql injection. …

▾ TwilightEPSS 0.43%via NVD
CVE-2026-13526High· 7.3
3mo ago

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_class.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. …

▾ TwilightEPSS 0.43%via NVD
CVE-2026-13525Medium· 6.3
3mo ago

A vulnerability was detected in CodeAstro Human Resource Management System 1.0

A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file application/models/Employee_model.php of the component Update_Earn_Leave Endpoint. The manipulatio…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13521High· 7.3
3mo ago

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functionality of the file /preview5.php. Such manipulation of the argument course_year_section lea…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-13520Medium· 6.3
3mo ago

A vulnerability was determined in itsourcecode Hospital Management System 1.0

A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Handler. This manipulation of the argument editid causes sql…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-13501Medium· 5.3
3mo ago

A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2

A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the component gofmt. The manipulation lead…

▾ SunlitEPSS 1.2%via NVD
CVE-2026-13500High· 7.3
3mo ago

A weakness has been identified in antlr ANTLR4 up to 4.13.2

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Handler. Executing a manipulation can lead…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-0864None
3mo ago

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the wr…

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the wr…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-54329High· 8.5
3mo ago

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection

▾ Twilightsnipe · snipe/snipe-itEPSS 0.39%via GHSA
CVE-2026-12789Medium· 4.7
3mo ago

A vulnerability was identified in ILIAS Learning Management System 11.0

A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::executeQueries of the file components/ILIAS/Tracking/classes/class.ilTrQuery.php of the component Learning Progress Track…

▾ SunlitEPSS 0.33%via NVD
GHSA-4jgr-pg2m-m988High
3mo ago

Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode

Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode

▾ Twilightdadrus · github.com/dadrus/heimdallvia GHSA
CVE-2026-11311High· 8.1
3mo ago

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Re…

▾ Twilightf5 · nginx_gateway_fabricEPSS 0.57%via NVD
CWE-74 vulnerabilities (CVEs) — page 11 · VulnSea